Executive brief
Google Chrome for iOS is a mobile web browser. A vulnerability in this version could allow a malicious website to bypass security boundaries and access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information, such as login sessions or personal data from other web services.
Technical details
An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 148.0.7778.216. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) restrictions via a specially crafted HTML page. By inducing a user to visit a malicious site, the attacker can leak cross-origin data from other domains. This is classified by Chromium as High severity. Users should update to version 148.0.7778.216 or later to mitigate this risk.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: CVE published to NVD dataset