Executive brief
A security vulnerability has been identified in Google Chrome's Federated Credential Management (FedCM) feature, which helps users sign into websites. A remote attacker could use a specially crafted webpage to bypass the browser's security boundaries that normally prevent different websites from accessing each other's data. If exploited, this could allow a malicious site to improperly interact with or access information from other websites the user is visiting.
Technical details
A Same-Origin Policy (SOP) bypass vulnerability exists in the Federated Credential Management (FedCM) component of Google Chrome. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries during certain FedCM operations. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass SOP protections, potentially leading to unauthorized cross-origin data access or interaction. The issue is resolved in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date