Junglewise Threat Intelligence

CVE-2026-13905: Google Chrome for iOS race condition in process memory

CVE-2026-13905 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A race condition vulnerability was identified in Google Chrome for iOS that could allow an individual with physical access to a device to view sensitive information. By exploiting a timing issue within the application's memory management, an attacker could potentially extract data from the browser's active memory. This could lead to the exposure of private user data or session information if the device is lost or stolen while the application is running.

Technical details

A race condition vulnerability exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw is triggered during specific process operations, allowing a local attacker with physical access to the device to exploit a timing window to read sensitive information directly from the application's process memory. This is classified as an information disclosure vulnerability resulting from improper synchronization. The issue has been addressed in the stable channel update 150.0.7871.47 for iOS.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats