Executive brief
Google Chrome on iOS contains an authorization flaw that could allow an attacker to bypass system-level access restrictions. An attacker can exploit this vulnerability by crafting a malicious HTML page and tricking a user into visiting it, potentially gaining unauthorized access to restricted functionality or data on the device.
Technical details
This vulnerability is an incorrect authorization flaw in the Mobile component of Google Chrome on iOS prior to version 152.0.7977.65. The vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page, requiring user interaction to visit the malicious page. The attack is delivered over the network and does not require prior authentication. Google has patched this issue in Chrome 152.0.7977.65 and later releases on iOS.
Affected products
- Google Chrome prior to 152.0.7977.65 on iOS
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65