Junglewise Threat Intelligence

CVE-2026-17826: Google Chrome for iOS cross-origin data leak via UI gestures

CVE-2026-17826 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to access data from other websites you have open. To trigger this, an attacker must trick a user into performing specific touch gestures or interactions on a specially crafted webpage. This could lead to the unauthorized disclosure of sensitive information across different web domains.

Technical details

A cross-origin data leak vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw stems from an inappropriate implementation in the browser's UI handling, which fails to strictly enforce origin boundaries during certain user interactions. A remote attacker can exploit this by convincing a user to engage in specific UI gestures on a malicious HTML page, potentially allowing the attacker to bypass Same-Origin Policy (SOP) protections and read data from other origins. This issue is addressed in the stable channel update 151.0.7922.72.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats