Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to access data from other websites you have open. This occurs due to a flaw in how the browser handles script injections, potentially leading to the exposure of sensitive user information. Users are advised to update their mobile browser to the latest version to prevent this cross-site data leakage.
Technical details
A vulnerability exists in the ScriptInjections component of Google Chrome for iOS prior to version 150.0.7871.47. The flaw results from an inappropriate implementation that fails to properly enforce cross-origin boundaries during script execution. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to leak sensitive data from different origins. This bypasses standard Same-Origin Policy (SOP) protections within the iOS-specific browser implementation. The issue is resolved in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched