Executive brief
A security vulnerability exists in Google Chrome for iOS, the mobile web browser used on iPhones and iPads. A remote attacker could use a specially crafted website to bypass security controls that normally restrict access to certain data or functions. This could potentially allow unauthorized access to information that should be protected by the browser's internal policies.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the Chrome for iOS component of Google Chrome. The flaw resides in how the browser handles discretionary access control (DAC) when processing web content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass intended access restrictions. The issue is resolved in version 151.0.7922.72 and later.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable Channel Update for Desktop/iOS released
- 2026-07-30: disclosed: NVD publication date