Executive brief
Google Chrome on iOS contains an information leak vulnerability in its password management feature that allows a local attacker to extract sensitive password data through a specially crafted file. This vulnerability could enable an attacker with physical or local access to a device to compromise saved credentials, potentially leading to unauthorized access to user accounts and services.
Technical details
CVE-2026-79207 is an information leak vulnerability in the Passwords component of Google Chrome on iOS. The vulnerability allows a local attacker to obtain sensitive information by providing a crafted file, requiring local access to the affected device. The attack does not require prior authentication or network access. An attacker exploiting this vulnerability could read stored password data or other sensitive credential information. The vulnerability was patched in Chrome 152.0.7977.65 for iOS.
Affected products
- Google Chrome prior to 152.0.7977.65 on iOS
Timeline
- 2026-08-25: disclosed