Impact
An information disclosure vulnerability exists in Google Chrome Mobile for iOS prior to version 152.0.7977.65. The flaw allows a local attacker to extract sensitive data through a local program, potentially revealing credentials, browsing history, or other private information. The weakness is identified as a data confidentiality issue (CWE-200). No remote or elevated privileges are required; the attack is limited to local execution environments.
Affected Systems
The affected product is Google Chrome for iOS. Versions earlier than 152.0.7977.65 are impacted. The issue was reported in Chromium issue 533121405 and a corresponding stable channel update was released on August 2026.
Risk and Exploitability
The Chromium security team rates the vulnerability with a CVSS score of 6.5, indicating moderate severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. Because it requires local access, the risk of widespread compromise is limited, but any user with local device control could exploit the flaw to read sensitive data. The moderate CVSS score and very low EPSS suggest the vulnerability is less likely to be widely reported but still merits prompt mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA