Junglewise Threat Intelligence

CVE-2026-13808: Google Chrome for iOS information disclosure via insufficient data validation

CVE-2026-13808 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for iOS could allow an individual with physical access to a device to extract sensitive information from the browser's memory. This affects the mobile version of the browser used on iPhones and iPads. An attacker could potentially access private data that remains in the system's active memory while the application is running.

Technical details

An information disclosure vulnerability exists in Google Chrome for iOS due to insufficient data validation. The flaw allows a local attacker with physical access to the mobile device to read sensitive information residing in the application's process memory. The vulnerability is categorized by Chromium as High severity. The issue was addressed in version 150.0.7871.47. Access to specific bug details in the Chromium tracker remains restricted to prevent further exploitation until a majority of users have updated.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-04-19: disclosed: Reported by Google internal researchers
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats