Executive brief
A vulnerability in Google Chrome's Federated Credential Management (FedCM) feature could allow a malicious website to bypass security boundaries. FedCM is a component that helps users sign into websites using third-party identity providers. If exploited, an attacker could potentially access data or perform actions on other websites that should normally be restricted by the browser's security rules.
Technical details
A Same Origin Policy (SOP) bypass vulnerability exists in the Federated Credential Management (FedCM) component of Google Chrome. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries under specific conditions. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass SOP, potentially leading to unauthorized access to sensitive data across different origins. This issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched