Authorization Bypass in Google Chrome by Remote Attacker
CVE-2026-102310

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102310?

A vulnerability has been identified in Google Chrome versions prior to 154.0.8037.92, where missing authorization in the Payments feature can be exploited. This flaw allows remote attackers who compromise the renderer process to bypass web origin policy restrictions through the use of specially crafted HTML pages, potentially leading to unauthorized access to sensitive data.

Affected Version(s)

Chrome 154.0.8037.92

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.