Executive brief
A security issue in Google Chrome for iOS could allow a malicious website to see where a user came from, even when that information should be hidden. This bypasses privacy settings designed to prevent websites from tracking a user's browsing path. While this does not allow for direct account takeover, it results in a minor loss of user privacy.
Technical details
An insufficient policy enforcement vulnerability exists in Google Chrome for iOS prior to version 150.0.7871.47. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which allows the attacker to bypass the 'no-referrer' security policy. This results in the leakage of referrer information that should have been suppressed by the browser's privacy controls. The vulnerability is classified by Chromium as Low severity and is addressed in the stable channel update.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched