CVE-2026-87449
Description
A flaw was found in Google Chrome. This cross-site request forgery (CSRF) vulnerability, which tricks a web browser into executing an unwanted action on a trusted site where the user is authenticated, specifically affects the DeviceBoundSessionCredentials feature. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, leading to a bypass of the web origin policy. This bypass could allow unauthorized actions to be performed on behalf of the user.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Understanding the Weakness (CWE)
Access Control,Other
Technical Impact: Gain Privileges or Assume Identity; Varies by Context; Bypass Protection Mechanism
An attacker can access any functionality that is inadvertently accessible to the source.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.