Executive brief
Google Chrome on iOS contains an information leak vulnerability that allows remote attackers to steal sensitive user information through a crafted webpage combined with social engineering. This could lead to exposure of passwords, personal data, or other confidential information that users believed to be secure.
Technical details
An information leak vulnerability exists in Google Chrome's mobile implementation on iOS prior to version 153.0.8010.36. The vulnerability is triggered via a crafted HTML page and requires user interaction (social engineering) to exploit. A remote attacker can leverage this flaw to exfiltrate sensitive information from the browser. The Chromium security team classified this as Low severity within their internal assessment, but the vulnerability received a CVSS score of 6.5 from external sources. The fix is available in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36 on iOS
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released