VYPR
Unrated severityNVD Advisory· Published Jul 1, 2026

Debian chromium: Insufficient validation of untrusted input in DeviceBoundSessionCredentials in G…

CVE-2026-13921

Description

Insufficient validation of untrusted input in DeviceBoundSessionCredentials in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

Affected products

2

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.