Executive brief
Google Chrome for iOS is a mobile web browser. A vulnerability in the way the browser handles certain web page elements could allow a malicious website to access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information from different web sessions.
Technical details
An inappropriate implementation in Chrome for iOS allowed for cross-origin data leakage. By enticing a user to visit a specially crafted HTML page, a remote attacker could bypass security boundaries to access data from other origins. This is a violation of the Same-Origin Policy (SOP). The vulnerability is addressed in version 151.0.7922.72. The issue was identified as having Medium severity by the Chromium project.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released
- 2026-07-30: disclosed: NVD publication date