Description
Side-channel information leakage in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exposes a side‑channel within the Safe Browsing component of Google Chrome on iOS. If an attacker can compromise the renderer process, a specially crafted HTML page can trigger the browser to reveal data that ordinarily would be protected by the same‑origin policy. This side‑channel information leak (CWE‑1300) enables the disclosure of cross‑origin data, undermining the browser’s isolation guarantees.

Affected Systems

Google Chrome for iOS versions earlier than 150.0.7871.47 are affected. The CVE listing does not specify additional patches beyond that version, so any iOS build older than the latest released Chrome should be assumed vulnerable until an explicit update is confirmed.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity. An EPSS score of less than 1% indicates a low but non‑zero probability of exploitation at present. The vulnerability is not in CISA’s KEV catalog. Exploitation requires the attacker first to gain control of a renderer process—likely through malicious web content or phishing attempts—and then to serve a crafted HTML page to activate the side‑channel. The attack vector is remote, web‑based, and contingent upon the renderer compromise.

Generated by OpenCVE AI on July 16, 2026 at 12:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome for iOS to version 150.0.7871.47 or later; the patch contains the Safe Browsing fix.
  • In managed device environments, enforce a browsing whitelist to restrict access to trusted sites and reduce the chance of loading malicious content.
  • If an immediate update is not possible, disable JavaScript for untrusted sites through a browser extension or enterprise policy to limit the renderer’s ability to process the crafted HTML page.

Generated by OpenCVE AI on July 16, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Chrome iOS Safe Browsing Side-Channel Information Leak

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome iOS Safe Browsing Side-Channel Information Leak

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leak in Chrome iOS Safe Browsing Allows Cross‑Origin Data Exposure

Sat, 11 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leak in Chrome iOS Safe Browsing Allows Cross‑Origin Data Exposure

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Side-Channel Leakage in Chrome iOS Safe Browsing Allows Cross-Origin Data Exposure

Thu, 09 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Side-Channel Leakage in Chrome iOS Safe Browsing Allows Cross-Origin Data Exposure

Wed, 08 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Side-Channel Data Leakage in Chrome for iOS Safe Browsing

Tue, 07 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Side-Channel Data Leakage in Chrome for iOS Safe Browsing

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leak in Chrome Safe Browsing on iOS

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leak in Chrome Safe Browsing on iOS

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage in Chrome Safe Browsing on iOS

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage in Chrome Safe Browsing on iOS

Sat, 04 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage in Google Chrome iOS Safe Browsing Allows Cross‑Origin Data Disclosure

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage in Google Chrome iOS Safe Browsing Allows Cross‑Origin Data Disclosure

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Side-Channel Leakage in Chrome Safe Browsing on iOS Enables Cross-Origin Data Exfiltration

Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Side-Channel Leakage in Chrome Safe Browsing on iOS Enables Cross-Origin Data Exfiltration

Thu, 02 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Safe Browsing Side‑Channel Leak in Chrome on iOS

Wed, 01 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Safe Browsing Side‑Channel Leak in Chrome on iOS

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Information Leakage via Renderer Compromise in Chrome Safe Browsing on iOS

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Information Leakage via Renderer Compromise in Chrome Safe Browsing on iOS

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Side-channel information leakage in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-1300
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:12:12.049Z

Reserved: 2026-06-29T23:03:23.053Z

Link: CVE-2026-13809

cve-icon Vulnrichment

Updated: 2026-07-01T15:32:12.117Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:45:05Z

Weaknesses
  • CWE-1300

    Improper Protection of Physical Side Channels