Executive brief
A security vulnerability in Google Chrome for iOS could allow an individual with physical access to a device to extract sensitive information from the browser's memory. This affects the mobile version of the browser used on iPhones and iPads. An attacker could potentially access private data that remains in the system's active memory while the application is running.
Technical details
An information disclosure vulnerability exists in Google Chrome for iOS due to insufficient data validation. The flaw allows a local attacker with physical access to the mobile device to read sensitive information residing in the application's process memory. The vulnerability is categorized by Chromium as High severity. The issue was addressed in version 150.0.7871.47. Access to specific bug details in the Chromium tracker remains restricted to prevent further exploitation until a majority of users have updated.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-04-19: disclosed: Reported by Google internal researchers
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory