PatchSiren cyber security CVE debrief
CVE-2026-8566 Google CVE debrief
A medium-severity vulnerability in Google Chrome on Android allows remote attackers to bypass discretionary access controls in the Payments component via a crafted HTML page. The flaw stems from insufficient policy enforcement and affects Chrome versions prior to 148.0.7778.168 on Android. Google has released a stable channel update to address this issue. The vulnerability was published on May 14, 2026, and last modified on May 19, 2026. No known exploitation in ransomware campaigns has been reported.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Android users who conduct financial transactions through Chrome browser; mobile application security teams; organizations with BYOD policies allowing Chrome on Android devices; payment processing security teams monitoring browser-based attack vectors
Technical summary
The vulnerability exists in the Payments component of Google Chrome on Android, where improper enforcement of security policies allows a remote attacker to bypass discretionary access controls. The attack requires user interaction (e.g., visiting a malicious HTML page) but does not require authentication or elevated privileges. Successful exploitation could allow unauthorized actions within the payment context, though confidentiality and availability impacts are not affected per CVSS scoring. The fix was released in Chrome stable channel version 148.0.7778.168.
Defensive priority
medium
Recommended defensive actions
- Update Google Chrome on Android to version 148.0.7778.168 or later
- Monitor for unexpected payment prompts or redirects while browsing
- Review payment-related permissions for installed web applications
- Apply security updates promptly as they become available through Google Play
Evidence notes
CVE description confirms insufficient policy enforcement in Payments component. CPE data indicates affected product as Google Chrome on Android with version bound excluding 148.0.7778.168. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N supports network attack vector with low attack complexity, no privileges required, but user interaction needed. CWE-284 (Improper Access Control) identified as secondary weakness.
Official resources
-
CVE-2026-8566 CVE record
CVE.org
-
CVE-2026-8566 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory, Release Notes
-
Source reference
[email protected] - Permissions Required
public