ZeroHour

CVE-2026-87615

PoC mass

Race Condition in Google Chrome Payments Enables UI Spoofing via Crafted Pages

CVSS 3.1
5.4 medium
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-87615 is a race condition (CWE-362) in the Payments component of Google Chrome that can let UI elements be spoofed due to a timing flaw in how payment interfaces are rendered. A remote attacker triggers it by using social engineering to lure a user to a crafted HTML page, exploiting the race window to make attacker-controlled content masquerade as legitimate Chrome payment UI. Successful spoofing could trick users into trusting or interacting with a fake payment interface, with limited confidentiality and availability impact per the CVSS 5.4 Medium rating. All Google Chrome users running versions prior to 153.0.8010.36 are affected. No exploitation has been observed in the wild (EPSS is 0.1%, not in CISA KEV), but one public proof-of-concept reference exists in the Chromium issue tracker.

What to do: Update Google Chrome to 153.0.8010.36 or later, verifying the version via chrome://settings/help; enterprises should push the update through browser management policies. Because exploitation depends on social engineering, remind users to be cautious with payment prompts triggered by web pages while updates roll out. No in-the-wild exploitation is currently known, so patching at the next regular update cycle is reasonable risk-based prioritization.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
massmulti-billion: roughly 3 billion+ Chrome users worldwide run Chrome across desktop and mobile — Chrome holds the largest global browser market share (roughly two-thirds of desktop browsing) with a multi-billion-user installed base, and the flaw affects every Chrome build prior to 153.0.8010.36, though actual exploitability requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.