CVE-2026-13862
Description
Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Chrome | — | 150.0.7871.47 < 150.0.7871.47 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Insufficient policy enforcement |
References (2)