Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to access data from other websites you have open. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of sensitive information across different browsing sessions. Users should update their mobile browser to the latest version to prevent this unauthorized data access.
Technical details
An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 149.0.7827.53. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit the vulnerability, an attacker must entice a user to visit a specifically crafted HTML page. Successful exploitation results in the unauthorized disclosure of information from other origins. The issue is addressed in version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel.
- 2026-06-04: disclosed: CVE published.