Description
Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential System Access Bypass
Action: Immediate Upgrade
AI Analysis

Impact

A missing authorization check in the Payments component of Google Chrome for Android versions older than 152.0.7977.65 could allow a remote attacker to bypass system access restrictions. By injecting a specially crafted HTML page and using social engineering, the attacker may manipulate the browser into executing payment-related actions that should normally be protected. This flaw corresponds to a missing authorization weakness (CWE-862) and could compromise the integrity of payment data or result in unauthorized transactions.

Affected Systems

Google Chrome running on Android devices with a version prior to 152.0.7977.65 is affected. No other vendors or product lines are listed as impacted.

Risk and Exploitability

The vulnerability is classified as medium severity (CVSS 4.3), with an EPSS score of `< 1%` and it is not listed in the CISA KEV catalog. The likely attack vector is a manipulated HTML page that an unsuspecting user opens, triggering the payment flow without proper authorization checks. Because the flaw requires user interaction and social engineering, exploitation probability is moderate but not negligible and may vary by user awareness.

Generated by OpenCVE AI on August 28, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later.
  • If an update is not immediately available, disable or restrict usage of Chrome for payment-related operations until a patch is released.
  • Avoid opening unexpected payment pages from untrusted sources or links that prompt for sensitive transaction details.

Generated by OpenCVE AI on August 28, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Fri, 28 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Android Chrome Payments Leading to Potential System Access Bypass

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Android Chrome Payments Leading to Potential System Access Bypass

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Payments in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:46:01.018Z

Reserved: 2026-08-25T06:08:09.379Z

Link: CVE-2026-79042

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:59.907

Modified: 2026-08-31T13:39:11.727

Link: CVE-2026-79042

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:00:14Z

Weaknesses