Sceawere

Vulnerability Detail

CVE-2026-79095UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Payments Information Leak

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Information leak
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Information leak in Payments in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-25T21:18:05.110Z",
  "pubdate": "2026-08-25T21:18:05.110Z",
  "executiveSummary": "A critical information disclosure vulnerability exists within the Payments component of Google Chrome prior to version 152.0.7977.65.\nThe vulnerability is classified as an information leak, allowing unauthorized cross-origin data access.\nAffected products include the Google Chrome browser ecosystem. By leveraging this flaw, a remote attacker can bypass standard browser security boundaries to exfiltrate sensitive cross-origin data.\nThe risk implication is significant as it undermines the Same-Origin Policy (SOP), potentially exposing user financial information or authentication tokens associated with the payment processing flow.\nSuccessful exploitation requires the victim to interact with a malicious, attacker-controlled HTML page. No authentication is required for the attacker to initiate the exploitation process, and the attack is executed within the context of the client-side browser environment.\nThis vulnerability is rated as Medium severity by the Chromium security team, necessitating prompt updates to remediate the underlying flaw in the affected component.",
  "technicalDetails": "The vulnerability resides in the Payments component of the Chromium architecture, specifically in how the browser handles cross-origin requests and data encapsulation during the payment orchestration process.\nThe root cause involves a failure in the security boundary enforcement mechanisms when processing payment-related data objects across different origins. The browser fails to correctly validate the origin of requests or ensure that sensitive data remains scoped to the initiating origin, allowing a malicious site to access data intended for other origins.\nThe exploitation method involves a remote attacker crafting a malicious HTML page containing specific scripts designed to trigger the vulnerability within the browser's Payment API handling logic. When a user navigates to the malicious page, the script initiates a request that circumvents the intended security controls.\nThe attack flow follows these steps: First, the attacker embeds a malicious script within a webpage. Second, when the target visits this page, the script targets the vulnerable Payment component. Third, due to the flaw in cross-origin validation, the browser incorrectly allows the malicious page to access data fields or responses that should be restricted by the Same-Origin Policy. Finally, the attacker captures this data and transmits it to an external server under their control.\nThe vulnerable component is the Payments sub-system within the browser's rendering engine. The issue affects all versions of Google Chrome preceding 152.0.7977.65. The exploit is executed client-side, requiring the victim to load the malicious payload via a standard web browser interface. The exploitation does not require the attacker to have prior authentication or elevated privileges on the victim's local machine, as the attack operates entirely within the sandbox-constrained browser environment.\nPost-exploitation, the impact involves the unauthorized disclosure of cross-origin information. Depending on the nature of the data handled by the Payments component at the time of the exploit, this could include sensitive payment credentials, session tokens, or personalized transaction metadata. This data leakage provides the attacker with actionable intelligence to perform further malicious activities, such as session hijacking or fraudulent transaction authorization."
}
CVE-2026-79095: Google Chrome Payments Information Leak (MEDIUM Severity, CVSS: 4.3) - Sceawere