Description
Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Payments
Action: Apply Update
AI Analysis

Impact

This vulnerability is a race condition in Chrome’s Payments component that allows a remote attacker to craft an HTML page that spoofs payment‑UI elements. By exploiting improper synchronization in the handling of payment‑UI events, the attacker can replace or manipulate these elements before they are rendered, creating a forged interface that appears legitimate. The attacker relies on user interaction and social engineering and can cause users to approve unauthorized transactions or reveal credentials through the deceived UI.

Affected Systems

The flaw affects all Google Chrome releases before version 153.0.8010.36 on every supported operating system. Users running an older build are vulnerable if they visit a malicious website that hosts the crafted payment interface.

Risk and Exploitability

The CVSS score is 5.4, which falls into the medium severity range, indicating that exploitation requires user interaction. The EPSS score is < 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote via a malicious webpage, and the risk is realistic in environments where users frequently interact with payment prompts and may not recognize phishing attempts.

Generated by OpenCVE AI on September 9, 2026 at 23:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • If the Payments feature is not required, disable the Payment Request API by setting the "Enable Payment Request API" flag to disabled in chrome://flags.
  • Provide user training on identifying legitimate payment dialogs and verifying transaction details before approving payments.

Generated by OpenCVE AI on September 9, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Payment Interface Spoofing Race Condition in Google Chrome

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Payment Interface Spoofing Race Condition in Google Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:44:24.599Z

Reserved: 2026-09-08T22:42:50.825Z

Link: CVE-2026-87615

cve-icon Vulnrichment

Updated: 2026-09-09T19:37:43.632Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:19.623

Modified: 2026-09-10T13:43:36.063

Link: CVE-2026-87615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:15:16Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')