Description
Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient enforcement of payment‑related policies in Google Chrome versions earlier than 151.0.7922.72 enables a remote attacker to execute a crafted HTML page that leaks data originating from other domains. The result is outbound exposure of sensitive payment information that is normally protected by same‑origin restrictions. This flaw allows disclosure of confidential data but does not permit code execution or direct system compromise.

Affected Systems

Google Chrome browsers running any version older than 151.0.7922.72 are impacted. The vulnerability was disclosed for all Chrome desktop channels (stable, beta…).

Risk and Exploitability

The CVSS score is 4.3, reflecting medium severity and limited impact. The EPSS score of less than 1% indicates a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a malicious web page that a victim visits, which then triggers the payment interaction and leaks cross‑origin data. Because the flaw is client‑side and requires user action to load the crafted page, the overall threat is moderate but the potential damage depends on the sensitivity of the leaked data.

Generated by OpenCVE AI on August 3, 2026 at 12:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to 151.0.7922.72 or later to apply the vendor fix.
  • If an immediate upgrade is not possible, configure the Chrome policy setting 'PaymentAPIAccess' to deny cross‑origin payment requests.
  • Review web applications to ensure that Payment API calls are restricted to trusted origins and that no sensitive data is sent to external domains without explicit user consent.

Generated by OpenCVE AI on August 3, 2026 at 12:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chrome Payments API Cross‑Origin Data Leak chromium-browser: chromium-browser: Insufficient policy enforcement in Payments
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 31 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Payments API Cross‑Origin Data Leak

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T14:39:06.590Z

Reserved: 2026-07-27T23:34:35.489Z

Link: CVE-2026-17742

cve-icon Vulnrichment

Updated: 2026-07-30T13:24:31.945Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:37.050

Modified: 2026-07-31T15:28:51.350

Link: CVE-2026-17742

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:09Z

Links: CVE-2026-17742 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:30:17Z

Weaknesses