Description
Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insecure implementation in the Payments component of Google Chrome on Android allowed a remote attacker, after compromising the renderer process, to serve a crafted HTML page that could fool a user into believing they were interacting with a legitimate domain. The flaw enables domain spoofing, potentially facilitating phishing and credential theft, without directly granting code execution or full system compromise. The weakness aligns with improper trust of input leading to user deception rather than traditional injection or privilege escalation. Simply put, an attacker could make a user think they are on a genuine vendor site when they are not, eroding confidentiality and user trust.

Affected Systems

Google Chrome on Android versions prior to 149.0.7827.53 are affected. Any device running an older stable channel version of Chrome for Android may be vulnerable unless patched to 149.0.7827.53 or later.

Risk and Exploitability

The CVSS assessment is marked as Medium, and the EPSS score is currently not available, suggesting no data on exploitation frequency. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to already have compromised the renderer process, a relatively high-privilege state within the browser. Consequently, while the impact is significant (domain spoofing can lead to credential compromise), the overall risk is moderate. Attackers would typically need a separate vulnerability or user to run malware that gains renderer control before leveraging this flaw.

Generated by OpenCVE AI on June 5, 2026 at 04:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on Android to version 149.0.7827.53 or later.
  • If an up‑to‑date update is not immediately available, disable or restrict the Payments functionality within Chrome via configuration or policies to mitigate the risk of domain spoofing.
  • As a temporary measure, monitor user reports of suspicious payment pages and consider implementing stricter site‑verification or domain‑validation checks in enterprise deployment.

Generated by OpenCVE AI on June 5, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Title Domain Spoofing via Insecure Payments Implementation in Chrome Android
Weaknesses CWE-269
CWE-606

Fri, 05 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:04:22.662Z

Reserved: 2026-06-04T17:06:30.671Z

Link: CVE-2026-11019

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:17:05.850

Modified: 2026-06-04T23:17:05.850

Link: CVE-2026-11019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T04:30:31Z

Weaknesses