Junglewise Threat Intelligence

CVE-2026-13908: Google Chrome for iOS input validation failure in Omnibox

CVE-2026-13908 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS contains a security flaw in the Omnibox (address bar) component. A remote attacker could trick a user into performing specific touch gestures to bypass security restrictions that normally prevent unauthorized navigation. This could potentially lead to users being directed to malicious websites or bypassing intended security boundaries within the browser.

Technical details

A vulnerability classified as improper input validation (CWE-20) exists in the Omnibox component of Google Chrome for iOS prior to version 150.0.7871.47. The flaw allows a remote attacker to bypass navigation restrictions by delivering malicious network traffic and convincing a user to perform specific UI gestures. This bypass could allow for unauthorized navigation actions that the browser's security policy would otherwise block. The issue was addressed in the stable channel update released in June 2026.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats