Junglewise Threat Intelligence

CVE-2026-17960: Google Chrome for iOS no-referrer policy bypass

CVE-2026-17960 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

Google Chrome for iOS is a mobile web browser. A vulnerability in this version could allow a malicious website to bypass privacy settings that normally hide where a user is coming from when they click a link. This could lead to the unintended disclosure of sensitive information contained in web addresses to third-party sites.

Technical details

An insufficient policy enforcement vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw resides in the handling of the 'no-referrer' policy, which is intended to prevent the browser from sending the Referer header to destination sites. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to bypass this privacy policy and leak referrer information. This is classified by Chromium as a Low severity issue. Users should update to version 151.0.7922.72 or later to mitigate this risk.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released
  • 2026-07-30: disclosed: NVD publication date

References

Related threats