ZeroHour

CVE-2026-87608

mass

Improper Certificate Validation in Google Chrome FedCM (pre-153.0.8010.36)

CVSS 3.1
7.5 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-87608 is an improper certificate validation flaw (CWE-295) in the Federated Credential Management (FedCM) component of Google Chrome in versions prior to 153.0.8010.36. A remote attacker could combine social engineering with crafted network traffic to bypass web origin policy, potentially impersonating or misattributing the origin in federated sign-in flows that use FedCM. Because the issue sits in a credential-federation API, a successful attack could undermine trust in "Sign in with..." identity flows, though Google rates the Chromium severity as Low despite a CVSS 3.1 base score of 7.5. All users running Chrome older than 153.0.8010.36 on any platform are affected. No public proof of concept is known, the CVE is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as possible; consumer installs should auto-update, so verify the browser has restarted to apply the patch. Enterprise administrators should confirm that update policies (e.g., delayed or frozen Chrome versions) do not hold devices on a vulnerable build, and prioritize this alongside the normal Chrome stable-channel rollout. No additional workaround is required given Chrome's auto-update mechanism and the currently low observed exploitation risk.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massPotentially hundreds of millions to billions of users (Chrome's installed base of roughly 3 billion), shrinking rapidly as auto-update distributes 153.0.8010.36 — Chrome holds roughly two-thirds of global browser market share with an installed base in the billions, so any unpatched pre-153.0.8010.36 installation is exposed until auto-update completes.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-295
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.