Junglewise Threat Intelligence

CVE-2026-13847: Google Chrome for iOS improper input validation cross-origin data leak

CVE-2026-13847 · Severity: info · CVSS 7.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for iOS, the mobile web browser used on iPhones and iPads. This flaw could allow a malicious website to bypass security boundaries and access data from other websites you have open. If exploited, an attacker could potentially steal sensitive information, such as login details or personal data, from other active web sessions.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Chrome for iOS component. The flaw stems from insufficient validation of untrusted input, which allows a remote attacker to bypass Same-Origin Policy (SOP) protections. By enticing a user to visit a specially crafted HTML page, an attacker can trigger a cross-origin data leak. This enables the unauthorized reading of sensitive information from different origins. The issue is resolved in Google Chrome for iOS version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats