Description
Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome for iOS contains a side-channel information leak in the WebAuthentication API that allows an attacker to obtain data from other origins. The defect, defined as CWE-1300, bypasses same‑origin restrictions so that a remote adversary can read sensitive information through a crafted HTML page. No code execution, privilege escalation, or denial of service is involved, but the confidentiality of data is compromised.

Affected Systems

All iOS devices running Chrome older than version 150.0.7871.47 are affected. The issue exists in every stable‑channel Chrome release until the browser is updated to the corrected build or the WebAuthentication API is disabled via policy.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting limited or no known widespread exploitation. Based on the description, the likely attack vector is a remote attacker hosting a malicious web page that triggers the WebAuthentication side‑channel; the compromised data remains across origins but remains confined to the information leakage scenario.

Generated by OpenCVE AI on July 31, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on all iOS devices to version 150.0.7871.47 via the App Store or a managed device policy, which removes the side‑channel flaw.
  • If the update cannot be deployed immediately, apply an enterprise policy that disables the WebAuthentication API in Chrome to block the side‑channel temporarily.
  • Maintain iOS firmware and Chrome at their latest releases by regularly installing updates and monitoring security advisories for any new patches or mitigations.

Generated by OpenCVE AI on July 31, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title WebAuthentication Side-Channel Information Leakage in Chrome iOS

Sat, 25 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title WebAuthentication Side-Channel Information Leakage in Chrome iOS

Wed, 22 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage via WebAuthentication API in Chrome for iOS

Thu, 16 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage via WebAuthentication API in Chrome for iOS

Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Side-Channel Leakage in Chrome iOS WebAuthentication API

Sun, 12 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Side-Channel Leakage in Chrome iOS WebAuthentication API

Fri, 10 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage via WebAuthentication in Chrome for iOS

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage via WebAuthentication in Chrome for iOS

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS WebAuthentication Side‑Channel Information Leakage

Tue, 07 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS WebAuthentication Side‑Channel Information Leakage

Mon, 06 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage via WebAuthentication in Chrome for iOS

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203

Mon, 06 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage via WebAuthentication in Chrome for iOS

Sun, 05 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title WebAuthentication API Side‑Channel Leak in Chrome for iOS

Sun, 05 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title WebAuthentication API Side‑Channel Leak in Chrome for iOS

Sat, 04 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage in WebAuthentication Exposes Cross‑Origin Data in Chrome for iOS

Sat, 04 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Side‑Channel Leakage in WebAuthentication Exposes Cross‑Origin Data in Chrome for iOS

Fri, 03 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Side‑channel Information Leakage via WebAuthentication in Chrome for iOS

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Side‑channel Information Leakage via WebAuthentication in Chrome for iOS

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via WebAuthentication in Chrome iOS

Thu, 02 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via WebAuthentication in Chrome iOS

Wed, 01 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome iOS WebAuthentication Side‑Channel Data Leak

Wed, 01 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Chrome iOS WebAuthentication Side‑Channel Data Leak

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-203
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Side‑Channel in Chrome iOS WebAuthentication

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Side‑Channel in Chrome iOS WebAuthentication

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-1300
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-06T18:56:11.630Z

Reserved: 2026-06-29T23:11:36.889Z

Link: CVE-2026-14074

cve-icon Vulnrichment

Updated: 2026-07-01T12:50:09.733Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:00:06Z

Weaknesses
  • CWE-1300

    Improper Protection of Physical Side Channels