Junglewise Threat Intelligence

CVE-2026-14074: Google Chrome for iOS side-channel leakage in WebAuthentication

CVE-2026-14074 · Severity: info · CVSS 3.3 · Published 2026-06-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to access data from other websites you have visited. This occurs through a technical flaw in how the browser handles web authentication, potentially compromising user privacy. Users should update their mobile browser to the latest version to resolve this issue.

Technical details

A side-channel information leakage vulnerability (CWE-1300) exists in the WebAuthentication component of Google Chrome for iOS prior to version 150.0.7871.47. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by enticing a user to visit a malicious HTML page. By exploiting this side channel, the attacker can leak sensitive data from different origins. The vulnerability is rated as Low severity by Chromium, and a fix is available in version 150.0.7871.47 and later.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats