Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13021

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

An inappropriate implementation flaw was found in the DeviceBoundSessionCredentials component of the Chromium browser. Upstream bug(s): https://code.google.com/p/chromium/issues/detail?id=511776603

Отчет

Important: An inappropriate implementation flaw in the DeviceBoundSessionCredentials component of the Chromium browser allows a remote attacker to bypass the same-origin policy. This vulnerability can be exploited by enticing a user to visit a specially crafted HTML page, potentially leading to unauthorized access to sensitive information or actions within the browser's context.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2492501chromium-browser: chromium-browser: Inappropriate implementation in DeviceBoundSessionCredentials

EPSS

Процентиль: 4%
0.00143
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
около 1 месяца назад

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

msrc
около 1 месяца назад

Chromium: CVE-2026-13021 Inappropriate implementation in DeviceBoundSessionCredentials

CVSS3: 4.3
debian
около 1 месяца назад

Inappropriate implementation in DeviceBoundSessionCredentials in Googl ...

CVSS3: 4.3
github
около 1 месяца назад

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 4%
0.00143
Низкий

8.8 High

CVSS3