Executive brief
Google Chrome for iOS is a popular web browser used by millions of iPhone and iPad users to browse the internet. A local attacker with access to the same device could exploit this vulnerability to read sensitive information from the browser's memory or data storage. This could expose user credentials, cached passwords, or personal browsing data without the user's knowledge or consent.
Technical details
This is an information disclosure vulnerability in the Mobile component of Google Chrome for iOS, affecting versions prior to 152.0.7977.65. The vulnerability allows a local attacker with access to the device to potentially obtain sensitive information via a local program. The attack requires local execution capability on the iOS device and does not require network access. The Chromium security team assigned this a Low severity rating internally, though it is tracked with a CVE identifier. A patch is available in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65