Executive brief
Google Chrome on iOS contained a race condition that could allow an attacker to bypass web origin policy protections through a specially crafted HTML page combined with social engineering. If exploited, this could enable unauthorized access to sensitive data or functionality from different websites.
Technical details
A race condition in the Mobile component of Google Chrome on iOS prior to version 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. The vulnerability required social engineering to be successfully exploited. The fix was included in Chrome 153.0.8010.36 released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36 on iOS
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched