PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8566 Google CVE debrief

A medium-severity vulnerability in Google Chrome on Android allows remote attackers to bypass discretionary access controls in the Payments component via a crafted HTML page. The flaw stems from insufficient policy enforcement and affects Chrome versions prior to 148.0.7778.168 on Android. Google has released a stable channel update to address this issue. The vulnerability was published on May 14, 2026, and last modified on May 19, 2026. No known exploitation in ransomware campaigns has been reported.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-19
Advisory published
2026-05-14
Advisory updated
2026-05-19

Who should care

Android users who conduct financial transactions through Chrome browser; mobile application security teams; organizations with BYOD policies allowing Chrome on Android devices; payment processing security teams monitoring browser-based attack vectors

Technical summary

The vulnerability exists in the Payments component of Google Chrome on Android, where improper enforcement of security policies allows a remote attacker to bypass discretionary access controls. The attack requires user interaction (e.g., visiting a malicious HTML page) but does not require authentication or elevated privileges. Successful exploitation could allow unauthorized actions within the payment context, though confidentiality and availability impacts are not affected per CVSS scoring. The fix was released in Chrome stable channel version 148.0.7778.168.

Defensive priority

medium

Recommended defensive actions

  • Update Google Chrome on Android to version 148.0.7778.168 or later
  • Monitor for unexpected payment prompts or redirects while browsing
  • Review payment-related permissions for installed web applications
  • Apply security updates promptly as they become available through Google Play

Evidence notes

CVE description confirms insufficient policy enforcement in Payments component. CPE data indicates affected product as Google Chrome on Android with version bound excluding 148.0.7778.168. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N supports network attack vector with low attack complexity, no privileges required, but user interaction needed. CWE-284 (Improper Access Control) identified as secondary weakness.

Official resources

public