CVE-2026-13021
Description
An inappropriate implementation flaw was found in the DeviceBoundSessionCredentials component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=511776603
Statement
Important: An inappropriate implementation flaw in the DeviceBoundSessionCredentials component of the Chromium browser allows a remote attacker to bypass the same-origin policy. This vulnerability can be exploited by enticing a user to visit a specially crafted HTML page, potentially leading to unauthorized access to sensitive information or actions within the browser's context.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.