Junglewise Threat Intelligence

CVE-2026-13862: Google Chrome for iOS policy enforcement bypass in Web Authentication

CVE-2026-13862 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for iOS affecting how the browser handles Web Authentication, including Passkeys and physical security keys. An attacker positioned on a compromised or malicious network could potentially trick the browser into leaking sensitive data across different websites using a specially crafted web page. This could lead to the exposure of private user information or authentication-related data.

Technical details

This vulnerability is classified as insufficient policy enforcement within the Web Authentication component (Passkeys and Security Keys) of Google Chrome for iOS. The flaw allows a remote attacker who occupies a privileged network position (such as a Man-in-the-Middle or a malicious local network) to facilitate cross-origin data leakage. By inducing a user to visit a crafted HTML page, the attacker can bypass intended security boundaries to access data from other origins. The issue is addressed in Google Chrome for iOS version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats