Junglewise Threat Intelligence

CVE-2026-87449: Google Chrome cross-site request forgery in DeviceBoundSessionCredentials

CVE-2026-87449 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's DeviceBoundSessionCredentials feature handles security authentication tokens for web sessions. A flaw in this feature allows a malicious website to craft HTML pages that bypass browser security protections, potentially hijacking user sessions or performing unauthorized actions on behalf of the user.

Technical details

This vulnerability is a cross-site request forgery (CSRF) flaw in Google Chrome's DeviceBoundSessionCredentials implementation prior to version 153.0.8010.36. The vulnerability allows a remote attacker to craft a malicious HTML page that bypasses the browser's web origin policy, a fundamental security boundary that prevents one website from accessing another's data or impersonating a user. No authentication or special user interaction is required beyond viewing the malicious page; the attacker only needs network-level access. The vulnerability was assigned Chromium's Medium security severity rating and received a CVSS score of 4.3. Chrome 153.0.8010.36 and later versions contain the fix.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87449 published on NVD
  • 2026-09-08: patched: Chrome 153.0.8010.36 released with fix

References

Related threats