Executive brief
A security vulnerability exists in the Reading List feature of Google Chrome for iOS. An attacker could trick a user into performing specific touch gestures on a malicious webpage to gain unauthorized elevated permissions within the browser. This could potentially allow the attacker to access data or perform actions they should not be able to, though the overall risk is considered low.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Reading List component of Google Chrome for iOS prior to version 149.0.7827.53. The flaw allows a remote attacker to achieve privilege escalation by convincing a user to perform specific UI gestures while visiting a specially crafted HTML page. The vulnerability stems from insufficient validation of untrusted input when processing these gestures. While the impact is categorized as privilege escalation, Chromium developers have assigned this a 'Low' severity rating. Users are advised to update to version 149.0.7827.53 or later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 stable channel update announced
- 2026-06-05: disclosed: CVE published to NVD