Description
Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: High)
Published: 2026-06-30
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient data validation in Google Chrome for iOS allows a local attacker who has physical access to the device to read potentially sensitive information from the process memory. The flaw maps to improper input validation (CWE‑20).

Affected Systems

Google Chrome for iOS versions prior to 150.0.7871.47 are affected.

Risk and Exploitability

The exploit requires direct physical access to the device, so it is a local attack. The CVSS score of 4.6 indicates a moderate impact level. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. While no public exploit exists, the Chromium security assessment labels it as high severity, underscoring the potential compromise of confidential data if an attacker succeeds.

Generated by OpenCVE AI on July 1, 2026 at 14:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on iOS to version 150.0.7871.47 or newer.
  • Enable a screen lock or other device‑level access controls to limit the opportunity for an attacker to gain physical access to an unlocked device.
  • Regularly check for and apply Chrome updates as they become available to ensure the vulnerability is remediated.

Generated by OpenCVE AI on July 1, 2026 at 14:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Local Information Leakage from Chrome for iOS Data Validation Flaw

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome for iOS Enabling Local Process Memory Leakage
Weaknesses CWE-200

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome for iOS Enabling Local Process Memory Leakage
Weaknesses CWE-200

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:18:42.605Z

Reserved: 2026-06-29T23:03:22.803Z

Link: CVE-2026-13808

cve-icon Vulnrichment

Updated: 2026-07-01T01:04:27.008Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T14:45:16Z

Weaknesses
  • CWE-20

    Improper Input Validation