Executive brief
Google Chrome's Federated Credential Management (FedCM) feature contained an authorization bypass that allowed attackers to circumvent web origin restrictions through a crafted HTML page. This could enable attackers to trick users into sharing credentials or authentication data with unintended websites, potentially compromising user accounts across multiple services.
Technical details
The vulnerability is a missing authorization check in Chrome's FedCM implementation prior to version 153.0.8010.36. An attacker can craft a malicious HTML page that exploits this authorization bypass to violate web origin policy restrictions, allowing unauthorized credential sharing between different origins. The attack requires user interaction (visiting a crafted webpage) but does not require authentication. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36