CVE-2026-87615
PoC massRace Condition in Google Chrome Payments Enables UI Spoofing via Crafted Pages
CVE-2026-87615 is a race condition (CWE-362) in the Payments component of Google Chrome that can let UI elements be spoofed due to a timing flaw in how payment interfaces are rendered. A remote attacker triggers it by using social engineering to lure a user to a crafted HTML page, exploiting the race window to make attacker-controlled content masquerade as legitimate Chrome payment UI. Successful spoofing could trick users into trusting or interacting with a fake payment interface, with limited confidentiality and availability impact per the CVSS 5.4 Medium rating. All Google Chrome users running versions prior to 153.0.8010.36 are affected. No exploitation has been observed in the wild (EPSS is 0.1%, not in CISA KEV), but one public proof-of-concept reference exists in the Chromium issue tracker.
What to do: Update Google Chrome to 153.0.8010.36 or later, verifying the version via chrome://settings/help; enterprises should push the update through browser management policies. Because exploitation depends on social engineering, remind users to be cautious with payment prompts triggered by web pages while updates roll out. No in-the-wild exploitation is currently known, so patching at the next regular update cycle is reasonable risk-based prioritization.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.