Executive brief
A security issue in Google Chrome for iOS could allow a malicious website to access information from other websites you have visited. This occurs through the browser's Autofill feature, which automatically completes forms for users. An attacker could use a specially designed webpage to trick the browser into leaking sensitive data, potentially compromising user privacy.
Technical details
An insufficient policy enforcement vulnerability exists in the Autofill component of Google Chrome for iOS. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak data across origins. By enticing a user to visit a specially crafted HTML page, the attacker can trigger the Autofill mechanism in a way that exposes sensitive information from a different origin. This vulnerability was addressed in Chrome for iOS version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-04: disclosed: NVD publication date