Description
Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Web Origin Policy Bypass via Code Injection
Action: Apply Patch
AI Analysis

Impact

A code injection flaw in the ReaderMode feature of Google Chrome on iOS allows an attacker to craft an HTML page that, when opened by a user, injects code that bypasses the browser’s same‑origin policy. By doing so, the attacker can read or modify content from the victim’s browsing context, potentially exfiltrating data or performing unauthorized actions. This is a classical Code Injection weakness, CWE‑94, and could compromise both confidentiality and integrity for the user’s data.

Affected Systems

Users of Google Chrome on iOS running versions earlier than 155.0.8059.39 are affected. No other products are listed, and the issue is confined to the ReaderMode mode in those releases.

Risk and Exploitability

The Chromium severity for this flaw is Medium, indicating a moderate risk. No CVSS score is disclosed and the EPSS score is not available, so exploitation likelihood is considered moderate. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to lure the user into opening a crafted HTML page, typically via social engineering such as phishing links. As no public exploit code is known, the overall risk remains moderate, but the potential impact is significant if the attack succeeds.

Generated by OpenCVE AI on October 6, 2026 at 21:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome on iOS to version 155.0.8059.39 or later, which resolves the injection flaw
  • If an update is not immediately possible, disable ReaderMode in Chrome’s settings to prevent the vulnerable code from executing
  • Implement user awareness training to avoid clicking malicious links or opening unknown HTML pages in Chrome on iOS

Generated by OpenCVE AI on October 6, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Code Injection in Chrome ReaderMode Enables Web Origin Policy Bypass on iOS

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Code injection in ReaderMode in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-94
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:19.068Z

Reserved: 2026-10-06T16:30:25.638Z

Link: CVE-2026-106189

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:44.977

Modified: 2026-10-06T19:58:37.060

Link: CVE-2026-106189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')