Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to access data from other websites you have visited. This occurs through a technical flaw in how the browser handles web authentication, potentially compromising user privacy. Users should update their mobile browser to the latest version to resolve this issue.
Technical details
A side-channel information leakage vulnerability (CWE-1300) exists in the WebAuthentication component of Google Chrome for iOS prior to version 150.0.7871.47. The flaw allows a remote attacker to bypass cross-origin isolation boundaries by enticing a user to visit a malicious HTML page. By exploiting this side channel, the attacker can leak sensitive data from different origins. The vulnerability is rated as Low severity by Chromium, and a fix is available in version 150.0.7871.47 and later.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched