Junglewise Threat Intelligence

CVE-2026-17842: Google Chrome for iOS Same Origin Policy bypass via UI gestures

CVE-2026-17842 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS is a mobile web browser. A vulnerability in this version could allow a malicious website to bypass security boundaries that normally prevent different websites from accessing each other's data. To succeed, an attacker would need to trick a user into performing specific touch gestures on a specially crafted webpage, potentially leading to the unauthorized access of sensitive information from other open sites.

Technical details

An inappropriate implementation in Google Chrome for iOS prior to version 151.0.7922.72 allowed for a Same Origin Policy (SOP) bypass. The vulnerability is triggered when a remote attacker convinces a user to engage in specific UI gestures on a crafted HTML page. This flaw allows the attacker to circumvent the security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. Google has addressed this issue in the stable channel update 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats