Junglewise Threat Intelligence

CVE-2026-13892: Google Chrome for iOS cross-origin data leak via UI gestures

CVE-2026-13892 · Severity: info · CVSS 5.4 · Published 2026-06-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to trick users into leaking private data. By convincing a user to perform specific touch gestures on a specially crafted webpage, an attacker could bypass security boundaries to access information from other websites. This could lead to the exposure of sensitive user data or browsing history.

Technical details

An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw allows a remote attacker to bypass cross-origin resource sharing (CORS) or similar security boundaries to leak data from different origins. Exploitation requires a victim to visit a malicious HTML page and be enticed into performing specific UI gestures. This is classified by Chromium as a Medium severity issue involving improper handling of cross-origin data during user interactions. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats