Junglewise Threat Intelligence

CVE-2026-87472: Google Chrome improper input validation in FedCM

CVE-2026-87472 · Severity: medium · CVSS 4.2 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Federated Credential Management (FedCM) feature contains an input validation flaw that allows an attacker with control over the renderer process to spoof UI elements displayed to users. This could enable phishing attacks or social engineering by displaying fake login dialogs or security warnings that appear legitimate to end users.

Technical details

The vulnerability is an improper input validation issue in Chrome's FedCM (Federated Credential Management) component. The attack requires an attacker to have already compromised the browser's renderer process, after which they can craft a malicious HTML page to spoof security-sensitive UI elements. The attack vector is local/renderer-context rather than unauthenticated network access. Exploitation allows visual spoofing of browser UI elements, potentially enabling credential theft or social engineering attacks. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed: Disclosed in Chrome 153 stable release announcement
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36 and later

References

Related threats