Executive brief
Google Chrome on iOS contains a flaw in its PriceTracking feature that allows an attacker to bypass system access restrictions to privileged pages through social engineering and crafted network traffic. This could enable unauthorized access to sensitive features that should only be accessible to trusted applications or users, potentially compromising user privacy or enabling unauthorized price manipulation.
Technical details
A confused deputy vulnerability exists in the PriceTracking component of Google Chrome on iOS versions prior to 153.0.8010.47. The vulnerability allows an attacker to leverage social engineering in combination with crafted network traffic to bypass system access restrictions and gain access to privileged pages. The attack requires user interaction (social engineering) and network-level access to craft malicious traffic. Successful exploitation grants unauthorized access to functionality that should be restricted, potentially allowing unauthorized data access or manipulation. The vulnerability is fixed in Chrome 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fix available in Chrome 153.0.8010.47