CVE-2026-13021

Description

An inappropriate implementation flaw was found in the DeviceBoundSessionCredentials component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=511776603

Statement

Important: An inappropriate implementation flaw in the DeviceBoundSessionCredentials component of the Chromium browser allows a remote attacker to bypass the same-origin policy. This vulnerability can be exploited by enticing a user to visit a specially crafted HTML page, potentially leading to unauthorized access to sensitive information or actions within the browser's context.

Frequently Asked Questions

Want to get errata notifications? Sign up here.