Junglewise Threat Intelligence

CVE-2026-13809: Google Chrome for iOS side-channel leakage in Safe Browsing

CVE-2026-13809 · Severity: info · CVSS 7.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for iOS within its Safe Browsing feature, which is designed to protect users from malicious websites. An attacker who has already partially compromised the browser's internal processing could use this flaw to bypass security boundaries and steal sensitive data from other websites the user is visiting. This could lead to the exposure of private information or login sessions across different web services.

Technical details

A side-channel information leakage vulnerability (CWE-1300) exists in the Safe Browsing component of Google Chrome for iOS. The flaw allows a remote attacker who has already achieved renderer process compromise to bypass Same-Origin Policy (SOP) protections. By utilizing a specially crafted HTML page, the attacker can infer and leak cross-origin data through side-channel analysis. This issue was addressed in version 150.0.7871.47. The vulnerability is categorized as High severity by Chromium developers.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-19: disclosed: Reported to Chromium by Google researchers.
  • 2026-06-30: patched: Fixed in Chrome for iOS version 150.0.7871.47.
  • 2026-06-30: advisory: NVD publication date.

References

Related threats