Impact
This CVE describes an insufficient enforcement of the no‑referrer policy in Google Chrome for iOS. When a user visits a specially crafted HTML page, the browser fails to honor the no‑referrer header, causing the document URL to be sent in the Referer header to third‑party domains. The underlying weakness is identified as CWE‑602, which involves information exposure through referrer headers.
Affected Systems
Google Chrome for iOS versions prior to 151.0.7922.72 are impacted. The issue affects only the mobile iOS variant of Chrome, and the fix is included in the stable channel update published in July 2026.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as Medium severity, which is reflected in the EPSS score of less than 1% and the absence of an entry in the CISA KEV catalog. Exploitation requires a mobile user to visit a malicious web page that uses a crafted page with the no‑referrer policy disabled. If successful, the attacker can learn the referrer that the user intended to keep private. Given the low score and exploitation constraints, the likelihood of widespread attack is low.
OpenCVE Enrichment
Debian DLA
Debian DSA