Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-13021

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Jun 24, 2026
Vendor unknown

Description

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

References