Executive brief
Google Chrome's DeviceBoundSessionCredentials feature handles security authentication tokens for web sessions. A flaw in this feature allows a malicious website to craft HTML pages that bypass browser security protections, potentially hijacking user sessions or performing unauthorized actions on behalf of the user.
Technical details
This vulnerability is a cross-site request forgery (CSRF) flaw in Google Chrome's DeviceBoundSessionCredentials implementation prior to version 153.0.8010.36. The vulnerability allows a remote attacker to craft a malicious HTML page that bypasses the browser's web origin policy, a fundamental security boundary that prevents one website from accessing another's data or impersonating a user. No authentication or special user interaction is required beyond viewing the malicious page; the attacker only needs network-level access. The vulnerability was assigned Chromium's Medium security severity rating and received a CVSS score of 4.3. Chrome 153.0.8010.36 and later versions contain the fix.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed: CVE-2026-87449 published on NVD
- 2026-09-08: patched: Chrome 153.0.8010.36 released with fix