Description
Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Assess Impact
AI Analysis

Impact

A race condition in Google Chrome’s mobile iOS implementation allows a remote attacker to bypass the browser’s web origin policy when a specially crafted HTML page is served. The flaw requires the victim to be social‑engineered into opening the malicious page, after which the attacker can read or manipulate content from a different origin without the usual same‑origin restrictions. This can enable cross‑origin data theft, manipulation of web pages, and potentially privilege escalation if combined with other browser features.

Affected Systems

The vulnerability affects Google Chrome Mobile on iOS versions prior to 153.0.8010.36. Versions 153.0.8010.36 and later include the fix and are not susceptible.

Risk and Exploitability

Because the flaw is low‑severity (CVSS 3.1) and relies on user interaction with a malicious web page, the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via browser, requiring social engineering to get the victim to load the crafted content. If exploited, the attacker can bypass origin restrictions, potentially leading to data exfiltration or unauthorized script execution.

Generated by OpenCVE AI on September 9, 2026 at 20:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome on iOS to version 153.0.8010.36 or later.
  • Enable Chrome’s Safe Browsing to detect malicious sites and enforce stricter content rules.
  • Educate users to avoid clicking unsolicited links and remain wary of unexpected web content.

Generated by OpenCVE AI on September 9, 2026 at 20:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Race Condition Allows Remote Web Origin Policy Bypass on Chrome Mobile iOS

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple iphone Os
Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple iphone Os
Google
Google chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allows Remote Web Origin Policy Bypass on Chrome Mobile iOS

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-367
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:23:51.100Z

Reserved: 2026-09-08T22:39:17.876Z

Link: CVE-2026-87517

cve-icon Vulnrichment

Updated: 2026-09-09T17:23:45.391Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:08.803

Modified: 2026-09-09T19:15:42.050

Link: CVE-2026-87517

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:00:08Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition