Junglewise Threat Intelligence

CVE-2026-9950: Google Chrome for iOS same origin policy bypass

CVE-2026-9950 · Severity: info · CVSS 8.3 · Published 2026-05-28

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

Google Chrome for iOS contains a security flaw that could allow a malicious website to access data from other websites you have open. This occurs when a site bypasses standard security boundaries, potentially leading to the exposure of sensitive information like login sessions or personal data. Users should update their Chrome app on iOS to the latest version to remain protected.

Technical details

A vulnerability exists in Google Chrome for iOS due to insufficient validation of untrusted input. An attacker who has already compromised the renderer process can exploit this flaw via a specially crafted HTML page to bypass the Same Origin Policy (SOP). This bypass allows the attacker to access data across security domains that should be isolated. The issue is fixed in version 148.0.7778.216. While the NVD entry lists 'info' severity, the Chromium project internally classifies this as 'High' severity.

Affected products

  • Google Chrome for iOS prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats