Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to access data from other websites. This occurs through a side-channel in the WebAuthentication component, which handles secure logins. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially compromising the privacy of the user's web sessions.
Technical details
A side-channel information leakage vulnerability exists in the WebAuthentication component of Google Chrome for iOS. The flaw is rooted in improper input validation (CWE-20), which allows a remote attacker to bypass cross-origin isolation boundaries. By enticing a user to visit a maliciously crafted HTML page, an attacker can leverage this side-channel to extract sensitive data from different origins. The vulnerability was addressed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched