Executive brief
A vulnerability in Google Chrome's session credential handling could allow a malicious website to bypass security boundaries. This could enable an attacker to access or interact with data from other websites you have open, potentially leading to unauthorized access to sensitive personal or corporate information. Users should update their browser to the latest version to mitigate this risk.
Technical details
This vulnerability exists in the DeviceBoundSessionCredentials component of Google Chrome. It is classified as an 'Inappropriate Implementation' that allows a remote attacker to bypass the Same Origin Policy (SOP). By convincing a user to visit a specially crafted HTML page, an attacker can execute scripts that interact with data from other origins. The issue was fixed in Chrome version 149.0.7827.197 for Windows and Mac, and 149.0.7827.196 for Linux. Google has assigned this a 'High' severity rating.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-05-10: disclosed: Reported to Chromium by Google researchers
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: advisory: NVD publication date