Junglewise Threat Intelligence

CVE-2026-17873: Google Chrome for iOS discretionary access control bypass

CVE-2026-17873 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for iOS, the mobile web browser used on iPhones and iPads. An attacker could use a specially designed website to bypass security controls that normally restrict access to certain data or functions. This could allow unauthorized actions to be performed within the browser context, potentially compromising the integrity of the user's browsing session.

Technical details

This vulnerability is classified as an insufficient policy enforcement flaw within the Chrome for iOS component. The root cause is a failure to properly validate or enforce discretionary access control (DAC) policies when processing web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass intended access restrictions, though the impact is limited to the browser's internal policy enforcement. The issue is resolved in Google Chrome for iOS version 151.0.7922.72.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for desktop and iOS versions.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats