Executive brief
Google Chrome's DeviceBoundSessionCredentials feature contains improper input validation that could allow an attacker to bypass the browser's web origin policy through social engineering and crafted network traffic. This could enable attackers to access or manipulate web sessions across different origins, potentially leading to unauthorized access to sensitive websites or user data.
Technical details
The vulnerability is an improper input validation flaw in Chrome's DeviceBoundSessionCredentials component, which handles session credential binding to device state. The vulnerability allows remote attackers to bypass web origin policy restrictions via crafted network traffic, requiring social engineering to exploit. No authentication is required as the attack is network-based. An attacker can craft malicious network packets to trick the browser into accepting credentials bound across different web origins. The vulnerability was patched in Chrome 152.0.7977.65, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65