Description
Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote Information Disclosure
Action: Apply Patch
AI Analysis

Impact

A discrepancy in Safebrowsing processing on iOS versions of Google Chrome prior to 155.0.8059.39 allowed a remote attacker who could compromise the renderer process to craft a malicious HTML page and exfiltrate sensitive data. The flaw falls under the input validation weakness identified as CWE‑203 and results in the disclosure of information that may be considered confidential to the user. The Chromium security severity is rated as Medium.

Affected Systems

All users of Google Chrome on iOS devices running a version earlier than 155.0.8059.39 are potentially vulnerable. The issue is specific to the renderer component and does not affect other browser components directly.

Risk and Exploitability

The vulnerability is not currently listed in the CISA KEV catalog and no EPSS score is available, indicating limited publicly known exploitation. The CVSS score of 5.3 classifies it as Medium severity. Exploitation requires an attacker to first compromise the renderer process, which would involve a separate chain of attack steps. Once that control is achieved, the attacker can serve a crafted HTML page to harvest data. Because the weakness is limited to information disclosure and does not grant arbitrary code execution, the overall risk remains Medium pending the adoption of the fix.

Generated by OpenCVE AI on October 7, 2026 at 00:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on iOS to version 155.0.8059.39 or later to eliminate the Safebrowsing discrepancy.
  • Ensure that the browser’s Safe Browsing feature is enabled to provide an additional layer of protection against malicious web content.
  • Set up automatic update enforcement for iOS Chrome to receive future security patches promptly.

Generated by OpenCVE AI on October 7, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 01:15:00 +0000

Type Values Removed Values Added
Title Chrome iOS Information Disclosure via Safebrowsing Discrepancy

Wed, 07 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:35:30.458Z

Reserved: 2026-10-06T16:36:13.066Z

Link: CVE-2026-106351

cve-icon Vulnrichment

Updated: 2026-10-06T19:35:11.866Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:03.803

Modified: 2026-10-06T20:17:23.590

Link: CVE-2026-106351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:00:09Z

Weaknesses