Junglewise Threat Intelligence

CVE-2026-87608: Google Chrome improper certificate validation in FedCM

CVE-2026-87608 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Federated Credential Management (FedCM) feature contains a certificate validation flaw that allows attackers to bypass web origin policy through social engineering. An attacker could trick users into accepting fraudulent identity provider authentication, potentially leading to account takeover or unauthorized access to web services that rely on federated identity.

Technical details

The vulnerability is an improper certificate validation flaw in Google Chrome's Federated Credential Management (FedCM) subsystem. The root cause is insufficient validation of SSL/TLS certificates presented during federated identity flows, allowing attackers to present invalid or spoofed certificates for identity providers. The attack requires network-level capability to intercept or manipulate traffic, combined with social engineering to convince users to proceed through browser warnings. An attacker exploiting this can bypass the web origin policy and potentially assume the identity of a legitimate identity provider, gaining unauthorized access to user accounts. The vulnerability is patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36

References

Related threats