Low chrome Logic Error 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactSide-channel information leakage in WebAuthentication
DescriptionSide-channel information leakage in WebAuthentication
ComponentWebAuthentication
Bug ClassLogic Error
Tracker511743480
Fix commit1c9475051b08 (chromium/src) +5/-6
CISA KEVNot listed
CreditedGoogle
Disclosed2026-06-30

Files Changed

  • components/webauthn/ios/passkey_tab_helper.mm
From 1c9475051b08cc12fa9c5259b5510d3f749deb12 Mon Sep 17 00:00:00 2001
From: Alexis Hétu <[email protected]>
Date: Thu, 14 May 2026 08:58:32 -0700
Subject: [PATCH] [iOS] Prevent potential cross-origin timing oracle in PasskeyTabHelper

This change ensures that relying party origin validation is
performed before checking for excluded passkeys during credential
creation in PasskeyTabHelper. By deferring the database query for
excluded passkeys until after the origin is verified, we prevent
a potential cross-origin timing oracle that could expose the
existence of passkeys to unauthorized origins.

This aligns the creation flow with the assertion flow, which
already correctly performs origin checks prior to accessing the
passkey store.

Bug: 511743480
Change-Id: I3b8641cd6d0e1b5f6f9d3024d58582020cc05ba9
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7836492
Reviewed-by: Tommy Martino <[email protected]>
Commit-Queue: Alexis Hétu <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1630652}
---

diff --git a/components/webauthn/ios/passkey_tab_helper.mm b/components/webauthn/ios/passkey_tab_helper.mm
index cf2092d..ffcd18b 100644
--- a/components/webauthn/ios/passkey_tab_helper.mm
+++ b/components/webauthn/ios/passkey_tab_helper.mm
@@ -340,11 +340,6 @@
   CHECK(request_type == PasskeyRequestParams::RequestType::kConditionalCreate ||
         request_type == PasskeyRequestParams::RequestType::kModal);
 
-  if (HasExcludedPasskey(params)) {
-    DeferToRenderer(web_frame, passkey_request_id, request_type);
-    return;
-  }
-
   const url::Origin& origin = web_frame->GetSecurityOrigin();
   const std::string& rp_id = params.RpId();
   if (!OriginIsAllowedToClaimRelyingPartyId(rp_id, origin)) {
@@ -386,9 +381,13 @@
 
 void PasskeyTabHelper::HandleRegistration(RegistrationRequestParams params) {
   IOSPasskeyClient::RequestInfo request_info = params.RequestInfo();
-
   PasskeyRequestParams::RequestType request_type = params.Type();
 
+  if (HasExcludedPasskey(params)) {
+    DeferToRenderer(std::move(request_info), request_type);
+    return;
+  }
+
   // This check is performed after the Incognito interstitial (if applicable)
   // has been shown and the user has chosen to proceed. This is intentional
   // as we only want to enforce these policies when we are ready to proceed
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.