Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to bypass certain security restrictions. By tricking a user into visiting a specially crafted webpage, an attacker could gain unauthorized access to data or perform actions that should normally be restricted by the browser's security policies. This issue primarily affects the privacy and access control mechanisms within the mobile browser.
Technical details
A vulnerability classified as insufficient policy enforcement exists in Google Chrome for iOS versions prior to 149.0.7827.53. The flaw resides in how the browser handles discretionary access control (DAC) when processing web content. A remote attacker can exploit this by hosting a specially crafted HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass intended security boundaries, potentially leading to unauthorized access to browser-managed data or restricted functionality. Google has addressed this issue in the stable channel update for version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-05: disclosed: CVE published to NVD