Description
Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypassing Web Origin Policy via Cross‑Site Request Forgery
Action: Patch
AI Analysis

Impact

A cross‑site request forgery flaw in Chrome’s DeviceBoundSessionCredentials allows a remote attacker to bypass the browser’s web origin policy through a crafted HTML page. The vulnerability could enable malicious sites to access or manipulate resources that should be restricted by same‑origin rules, potentially leading to credential theft or data exfiltration. The reported severity is Medium.

Affected Systems

Google Chrome desktop builds older than 153.0.8010.36 on all supported operating systems are affected. Users running these versions should be aware of the risk.

Risk and Exploitability

The CVSS score of 4.3 places the vulnerability in the Medium severity range. The EPSS score of less than 1% indicates a very low exploitation probability, and the flaw is not listed in the CISA KEV catalog, pointing to limited public exploitation data. Exploitation would still require a user to open a maliciously crafted page in Chrome, making the attack vector user‑dependent. The absence of publicly disclosed exploits suggests a lower immediate risk, but the flaw remains actionable if an attacker can entice a user to visit a malicious site.

Generated by OpenCVE AI on September 9, 2026 at 19:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later.
  • If an update is not immediately possible, disable DeviceBoundSessionCredentials via Chrome flags or enterprise policy if available.
  • Avoid visiting untrusted or suspicious web pages that could host malicious crafted HTML.

Generated by OpenCVE AI on September 9, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cross‑site request forgery enables origin policy bypass in Chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Cross‑site request forgery enables origin policy bypass in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-352
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:26:38.103Z

Reserved: 2026-09-08T22:23:06.385Z

Link: CVE-2026-87449

cve-icon Vulnrichment

Updated: 2026-09-09T17:25:13.111Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:01.227

Modified: 2026-09-09T20:29:53.350

Link: CVE-2026-87449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:15:07Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)