Description
Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

This vulnerability involves an observable discrepancy in the Safebrowsing service of Google Chrome on iOS. An attacker who can compromise the renderer process could serve a specially crafted HTML page that would lead to the disclosure of sensitive data. The flaw is categorized as a default-data-encapsulation error, as identified by CWE‑203, and is rated as medium severity by Chromium. Importantly, the vulnerability does not allow arbitrary code execution or direct destruction of services, but it does expose information that can be leveraged for further attacks or credential theft.

Affected Systems

The flaw is present in Chrome for iOS versions earlier than 153.0.8010.36. Users running any older stable channel build on iOS devices are vulnerable. No other platforms or plugins are listed as affected.

Risk and Exploitability

Because the flaw requires the attacker to first compromise the renderer process, the attack vector is more limited than a remote code execution path; however, once the renderer is compromised, sensitive data can be exfiltrated via a crafted web page. Although the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, the medium severity rating and the potential impact on confidentiality warrant prompt remediation.

Generated by OpenCVE AI on September 9, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome for iOS version 153.0.8010.36 or newer.
  • Verify that the device’s iOS update status is current and that Chrome’s auto‑update feature is enabled.
  • If the update cannot be applied immediately, use an alternative browser when accessing untrusted sites until Chrome is updated.

Generated by OpenCVE AI on September 9, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Safebrowsing Discrepancy Allows Information Disclosure in Chrome for iOS

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple iphone Os
Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple iphone Os
Google
Google chrome

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Safebrowsing Discrepancy Allows Information Disclosure in Chrome for iOS

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T14:33:05.084Z

Reserved: 2026-09-08T22:39:19.510Z

Link: CVE-2026-87518

cve-icon Vulnrichment

Updated: 2026-09-09T14:32:54.188Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:08.917

Modified: 2026-09-09T18:12:57.413

Link: CVE-2026-87518

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses