CVE-2026-103630: Use after free in FedCM
Published Sep 4, 2026
·Updated
Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Credit
xinyang
Affected Software
2 affected componentsFixes available
Google Chrome<154.0.8037.97
Google Chrome<154.0.8037.97
154.0.8037.97
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154.0.8037.97
Event History
Sep 4, 2026
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Oct 2, 2026
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.