Description
Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker can cause an information leak by delivering a specially crafted file that is opened by Google Chrome on iOS versions before 152.0.7977.65. The vulnerability, classified as CWE-200, allows the attacker to read sensitive information that should not be exposed through the browser’s handling of that file. Because the flaw is limited to local access and has been deemed of low severity by Chromium’s assessment, the impact is primarily a privacy violation rather than a compromise of system integrity or availability.

Affected Systems

The affected product is Google Chrome for iOS, specifically all releases prior to version 152.0.7977.65. Users running those older releases on iOS devices are susceptible to the leak if they receive or open crafted files.

Risk and Exploitability

Detailed exploitation likelihood is not quantified in the EPSS database and the vulnerability is not listed in the CISA KEV catalog, indicating the current risk exposure is modest. The attack vector requires local access or the ability to supply a malicious file to the device, which in practice limits the potential for widespread exploitation. No public zero-day exploits have been reported, but the flaw still warrants a remedial action to prevent private data leakage.

Generated by OpenCVE AI on August 25, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on iOS to version 152.0.7977.65 or newer to remove the flaw
  • Avoid opening or executing files from untrusted sources on the device
  • Enable or enforce local file protection policies and consider uninstalling older Chrome versions

Generated by OpenCVE AI on August 25, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local Information Leak via Crafted File in iOS Chrome Versions Prior to 152.0.7977.65

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a crafted file. (Chromium security severity: Low)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-25T20:10:58.836Z

Reserved: 2026-08-25T06:05:04.664Z

Link: CVE-2026-78957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:51.737

Modified: 2026-08-25T21:17:51.737

Link: CVE-2026-78957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor