Description
Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low)
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An information disclosure vulnerability exists in Google Chrome Mobile for iOS prior to version 152.0.7977.65. The flaw allows a local attacker to extract sensitive data through a local program, potentially revealing credentials, browsing history, or other private information. The weakness is identified as a data confidentiality issue (CWE-200). No remote or elevated privileges are required; the attack is limited to local execution environments.

Affected Systems

The affected product is Google Chrome for iOS. Versions earlier than 152.0.7977.65 are impacted. The issue was reported in Chromium issue 533121405 and a corresponding stable channel update was released on August 2026.

Risk and Exploitability

The Chromium security team has rated the vulnerability as low severity. An EPSS score is not available, and the vulnerability does not appear in the CISA KEV catalog. The local nature of the exploit reduces the likelihood of widespread compromise, but any user with local access to the device could read sensitive information. Prompt remediation is advised.

Generated by OpenCVE AI on August 25, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update for iOS, version 152.0.7977.65 or newer.
  • If an immediate update is not possible, disable or restrict local applications that can interact with Chrome or remove the vulnerable Chrome installation.
  • Monitor app permissions and data leakage using security tools and ensure no sensitive data is exposed through local channels.
  • Regularly review security patches and advisories from Google Chrome for any related vulnerabilities.

Generated by OpenCVE AI on August 25, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure in Chrome Mobile for iOS

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low)
Weaknesses CWE-200
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-25T20:10:58.637Z

Reserved: 2026-08-25T06:06:37.570Z

Link: CVE-2026-78981

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:54.537

Modified: 2026-08-25T21:17:54.537

Link: CVE-2026-78981

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor