Описание
Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
An inappropriate implementation flaw was found in the DeviceBoundSessionCredentials component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=511776603
Отчет
Important: An inappropriate implementation flaw in the DeviceBoundSessionCredentials component of the Chromium browser allows a remote attacker to bypass the same-origin policy. This vulnerability can be exploited by enticing a user to visit a specially crafted HTML page, potentially leading to unauthorized access to sensitive information or actions within the browser's context.
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials
Inappropriate implementation in DeviceBoundSessionCredentials in Googl ...
Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
EPSS
8.8 High
CVSS3