Junglewise Threat Intelligence

CVE-2026-87518: Google Chrome observable discrepancy in Safe Browsing on iOS

CVE-2026-87518 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Google Chrome, Apple Iphone Os. Vendors: Google, Apple.

Executive brief

Google Chrome on iOS includes a Safe Browsing feature that helps protect users from malicious websites. A flaw in how this feature detects suspicious content could allow an attacker to bypass safety checks and deliver malicious pages to users, potentially leading to malware installation or credential theft.

Technical details

The vulnerability is an observable discrepancy (information disclosure) in the Safe Browsing component of Google Chrome on iOS. The issue requires the attacker to first compromise the renderer process; the attacker can then craft a malicious HTML page that exploits this inconsistency in Safe Browsing logic to obtain sensitive information or bypass safety checks. This is a post-compromise attack vector requiring renderer process access. The vulnerability was fixed in Chrome 153.0.8010.36 for iOS and assigned Chromium security severity: Medium.

Affected products

  • Google Chrome prior to 153.0.8010.36 on iOS

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released for iOS

References

Related threats