PatchSiren cyber security CVE debrief
CVE-2026-8566 Google CVE debrief
A medium-severity vulnerability in Google Chrome on Android allows remote attackers to bypass discretionary access controls in the Payments component via a crafted HTML page. The flaw stems from insufficient policy enforcement and affects Chrome versions prior to 148.0.7778.168 on Android. Google has released a stable channel update to address this issue. The vulnerability was published on May 14, 2026, and last modified on May 19, 2026. No known exploitation in ransomware campaigns has been reported.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Android users who conduct financial transactions through Chrome browser; mobile application security teams; organizations with BYOD policies allowing Chrome on Android devices; payment processing security teams monitoring browser-based attack vectors
Technical summary
The vulnerability exists in the Payments component of Google Chrome on Android, where improper enforcement of security policies allows a remote attacker to bypass discretionary access controls. The attack requires user interaction (e.g., visiting a malicious HTML page) but does not require authentication or elevated privileges. Successful exploitation could allow unauthorized actions within the payment context, though confidentiality and availability impacts are not affected per CVSS scoring. The fix was released in Chrome stable channel version 148.0.7778.168.
Defensive priority
medium
Recommended defensive actions
- Update Google Chrome on Android to version 148.0.7778.168 or later
- Monitor for unexpected payment prompts or redirects while browsing
- Review payment-related permissions for installed web applications
- Apply security updates promptly as they become available through Google Play
Evidence notes
CVE description confirms insufficient policy enforcement in Payments component. CPE data indicates affected product as Google Chrome on Android with version bound excluding 148.0.7778.168. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N supports network attack vector with low attack complexity, no privileges required, but user interaction needed. CWE-284 (Improper Access Control) identified as secondary weakness.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8566 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8566
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8566 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8566
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html
[email protected] - Vendor Advisory, Release Notes
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/470646792
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.