Executive brief
A security vulnerability has been identified in Google Chrome's session credential management. An attacker could use a specially crafted website to bypass security boundaries that normally prevent different websites from accessing each other's data. This could potentially allow an attacker to access sensitive session information or perform unauthorized actions on behalf of the user.
Technical details
A Same Origin Policy (SOP) bypass vulnerability exists in Google Chrome's DeviceBoundSessionCredentials component. The flaw stems from improper input validation of untrusted data, which allows a remote attacker to bypass origin-based security restrictions via a crafted HTML page. An attacker who successfully lures a user to a malicious site could potentially access data across origin boundaries. This issue is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched