Executive brief
Google Chrome's Federated Credential Management (FedCM) feature contains a certificate validation flaw that allows attackers to bypass web origin policy through social engineering. An attacker could trick users into accepting fraudulent identity provider authentication, potentially leading to account takeover or unauthorized access to web services that rely on federated identity.
Technical details
The vulnerability is an improper certificate validation flaw in Google Chrome's Federated Credential Management (FedCM) subsystem. The root cause is insufficient validation of SSL/TLS certificates presented during federated identity flows, allowing attackers to present invalid or spoofed certificates for identity providers. The attack requires network-level capability to intercept or manipulate traffic, combined with social engineering to convince users to proceed through browser warnings. An attacker exploiting this can bypass the web origin policy and potentially assume the identity of a legitimate identity provider, gaining unauthorized access to user accounts. The vulnerability is patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36