CVE-2026-8013Disclosure(apple / chrome)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-07)
  • 3 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 205-0605-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-072
Disclosure1General1
Full discourse3 posts
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-8013 (FedCM input validation): “low severity” but it targets the identity plumbing. This matters because Microsoft/Chrome are fighting tracking, yet one crafted page can still pry post-click. #Windows #Security https://windowsforum.com/threads/cve-2026-8013-fedcm-flaw-chrome-148-patch-guidance-for-windows-edge.416877/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #FedcmSecurity #Chrome148Update https://t.co/UTPpXG5t1G

    Post summary

    The tweet provides a disclosure of CVE‑2026‑8013, noting its low severity and potential to compromise identity plumbing via a crafted page, but it does not mention any PoC, exploit, active exploitation, or patch information.

    0000036
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8013 Cross-Origin Data Leak in Google Chrome FedCM Prior to 148.0.7778.96 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8013

    Post summary

    The post notes CVE-2026-8013 as a cross‑origin data leak in Google Chrome FedCM before version 148.0.7778.96, but provides no PoC, exploitation details, or patch information.

    0000056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8013 Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page.… https://www.cve.org/CVERecord?id=CVE-2026-8013

    Post summary

    The text references CVE‑2026‑8013, indicating that insufficient input validation in Chrome’s FedCM can lead to cross‑origin data leakage via a crafted HTML page, with no mention of PoC, exploitation, patches, or debunking.

    0000087
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more