Junglewise Threat Intelligence

CVE-2026-13889: Google Chrome side-channel information leakage in WebAuthentication

CVE-2026-13889 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to access data from other websites. This occurs through a side-channel in the WebAuthentication component, which handles secure logins. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially compromising the privacy of the user's web sessions.

Technical details

A side-channel information leakage vulnerability exists in the WebAuthentication component of Google Chrome for iOS. The flaw is rooted in improper input validation (CWE-20), which allows a remote attacker to bypass cross-origin isolation boundaries. By enticing a user to visit a maliciously crafted HTML page, an attacker can leverage this side-channel to extract sensitive data from different origins. The vulnerability was addressed in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats