Impact
An information disclosure vulnerability exists in Google Chrome Mobile for iOS prior to version 152.0.7977.65. The flaw allows a local attacker to extract sensitive data through a local program, potentially revealing credentials, browsing history, or other private information. The weakness is identified as a data confidentiality issue (CWE-200). No remote or elevated privileges are required; the attack is limited to local execution environments.
Affected Systems
The affected product is Google Chrome for iOS. Versions earlier than 152.0.7977.65 are impacted. The issue was reported in Chromium issue 533121405 and a corresponding stable channel update was released on August 2026.
Risk and Exploitability
The Chromium security team has rated the vulnerability as low severity. An EPSS score is not available, and the vulnerability does not appear in the CISA KEV catalog. The local nature of the exploit reduces the likelihood of widespread compromise, but any user with local access to the device could read sensitive information. Prompt remediation is advised.
OpenCVE Enrichment