CVE-2026-87608
massImproper Certificate Validation in Google Chrome FedCM (pre-153.0.8010.36)
CVE-2026-87608 is an improper certificate validation flaw (CWE-295) in the Federated Credential Management (FedCM) component of Google Chrome in versions prior to 153.0.8010.36. A remote attacker could combine social engineering with crafted network traffic to bypass web origin policy, potentially impersonating or misattributing the origin in federated sign-in flows that use FedCM. Because the issue sits in a credential-federation API, a successful attack could undermine trust in "Sign in with..." identity flows, though Google rates the Chromium severity as Low despite a CVSS 3.1 base score of 7.5. All users running Chrome older than 153.0.8010.36 on any platform are affected. No public proof of concept is known, the CVE is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as possible; consumer installs should auto-update, so verify the browser has restarted to apply the patch. Enterprise administrators should confirm that update policies (e.g., delayed or frozen Chrome versions) do not hold devices on a vulnerable build, and prioritize this alongside the normal Chrome stable-channel rollout. No additional workaround is required given Chrome's auto-update mechanism and the currently low observed exploitation risk.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper certificate validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.