Junglewise Threat Intelligence

CVE-2026-9955: Google Chrome cross-origin data leak in iOS

CVE-2026-9955 · Severity: info · CVSS 7.5 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS is a mobile web browser. A vulnerability in this version could allow a malicious website to bypass security boundaries and access data from other websites you have open. This could lead to the unauthorized disclosure of sensitive information, such as login sessions or personal data from other web services.

Technical details

An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 148.0.7778.216. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) restrictions via a specially crafted HTML page. By inducing a user to visit a malicious site, the attacker can leak cross-origin data from other domains. This is classified by Chromium as High severity. Users should update to version 148.0.7778.216 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: CVE published to NVD dataset

References

Related threats