Junglewise Threat Intelligence

CVE-2026-13913: Google Chrome insufficient policy enforcement in Autofill on iOS

CVE-2026-13913 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Autofill feature of Google Chrome on iOS could allow a malicious website to access data from other websites. To exploit this, an attacker would need to trick a user into performing specific touch gestures on a specially crafted webpage. This could result in the unauthorized disclosure of sensitive information stored in the browser's autofill system.

Technical details

An insufficient policy enforcement vulnerability exists in the Autofill component of Google Chrome for iOS. The flaw allows a remote attacker to bypass cross-origin data protections by inducing a user to perform specific UI gestures on a malicious HTML page. Successful exploitation enables the attacker to leak sensitive data across origins. The vulnerability is addressed in version 150.0.7871.47 and later. Chromium developers have assigned this a Medium severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats