Description
Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)
Published: 2026-08-25
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure
Action: Apply patch
AI Analysis

Impact

A local attacker can cause an information leak by delivering a specially crafted file that is opened by Google Chrome on iOS versions before 152.0.7977.65. The vulnerability, classified as CWE-200, allows the attacker to read sensitive information that should not be exposed through the browser’s handling of that file. Because the flaw is limited to local access and has been deemed of low severity by Chromium’s assessment, the impact is primarily a privacy violation rather than a compromise of system integrity or availability.

Affected Systems

The affected product is Google Chrome for iOS, specifically all releases prior to version 152.0.7977.65. Users running those older releases on iOS devices are susceptible to the leak if they receive or open crafted files.

Risk and Exploitability

The CVSS score is 5.5, indicating a moderate risk. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating that the current risk exposure is modest. The attack vector requires local access or the ability to supply a malicious file to the device, which in practice limits the potential for widespread exploitation. The flaw still warrants a remedial action to prevent private data leakage.

Generated by OpenCVE AI on August 26, 2026 at 21:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on iOS to version 152.0.7977.65 or newer to remove the flaw
  • Avoid opening or executing files from untrusted sources on the device
  • Enable or enforce local file protection policies and consider uninstalling older Chrome versions

Generated by OpenCVE AI on August 26, 2026 at 21:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 02 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple iphone Os
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple iphone Os

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Local Information Leak via Crafted File in iOS Chrome Versions Prior to 152.0.7977.65

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local Information Leak via Crafted File in iOS Chrome Versions Prior to 152.0.7977.65

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:34:12.116Z

Reserved: 2026-08-25T06:05:04.664Z

Link: CVE-2026-78957

cve-icon Vulnrichment

Updated: 2026-08-26T18:23:33.043Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:51.737

Modified: 2026-09-02T00:13:50.113

Link: CVE-2026-78957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor