Junglewise Threat Intelligence

CVE-2026-87626: Google Chrome authorization bypass in DeviceBoundSessionCredentials

CVE-2026-87626 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an authorization flaw in its DeviceBoundSessionCredentials component that allows a remote attacker to bypass web origin policy restrictions using crafted network traffic. An attacker could exploit this to access or manipulate user data from websites the victim visits, potentially leading to session hijacking or data theft without proper origin validation.

Technical details

This vulnerability is an incorrect authorization flaw in the DeviceBoundSessionCredentials component of Google Chrome. The root cause stems from improper validation of web origin policy during credential handling. An attacker can send crafted network traffic to bypass these authorization checks, allowing unauthorized access to session credentials or sensitive data bound to specific origins. No user interaction is required; the vulnerability is exploitable remotely. The flaw was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats