Insufficient Input Validation in FedCM of Google Chrome
CVE-2026-8013

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-8013?

A flaw in the FedCM feature of Google Chrome enables remote attackers to exploit insufficient validation of untrusted input. This vulnerability allows the leakage of cross-origin data through specially crafted HTML pages, posing a risk to user privacy and data security. It's crucial for users and administrators to keep their browsers updated to mitigate potential threats associated with this vulnerability.

Affected Version(s)

Chrome 148.0.7778.96

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.