Junglewise Threat Intelligence

CVE-2026-87482: Google Chrome cleartext transmission in HttpsUpgrades on iOS

CVE-2026-87482 · Severity: medium · CVSS 5.9 · Published 2026-09-09

Technologies: Google Chrome, Apple Iphone Os. Vendors: Google, Apple.

Executive brief

Google Chrome on iOS contains a vulnerability in its HTTPS upgrade mechanism that allows sensitive data to be transmitted in cleartext. A remote attacker can exploit this via crafted network traffic to intercept and leak user information. This could expose credentials, session tokens, or other sensitive data transmitted through the browser.

Technical details

The vulnerability is a cleartext transmission issue in the HttpsUpgrades component of Google Chrome on iOS versions prior to 153.0.8010.36. The root cause involves the failure to properly encrypt or upgrade HTTP connections to HTTPS in specific scenarios. A remote attacker can craft malicious network traffic to trigger the cleartext transmission of sensitive data. The attack requires network access to intercept traffic but does not require user authentication or active user interaction beyond normal browsing. Patch is available in Chrome 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36 on iOS

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats