Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to bypass security restrictions. By tricking a user into visiting a specially crafted webpage, an attacker could gain unauthorized access to certain data or bypass privacy controls. This issue primarily affects the mobile version of the browser on iPhones and iPads.
Technical details
A vulnerability classified as insufficient policy enforcement exists in Google Chrome for iOS prior to version 149.0.7827.53. The flaw resides within the browser's handling of discretionary access control (DAC) mechanisms. A remote attacker can exploit this by hosting a specially crafted HTML page and inducing a user to visit it. Successful exploitation allows the attacker to bypass intended access restrictions, potentially leading to unauthorized information disclosure or security policy circumvention. Google has addressed this issue in the stable channel update for version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-05: disclosed: CVE published to NVD