Sceawere

Vulnerability Detail

CVE-2026-78981UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome iOS Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Information leak
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to potentially obtain sensitive information via a local program. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-25T21:17:54.537Z",
  "pubdate": "2026-08-25T21:17:54.537Z",
  "executiveSummary": "This vulnerability involves an information leak within Google Chrome for iOS, which is classified by the Chromium project as having a Low security severity.\nThe flaw enables a local attacker to potentially gain unauthorized access to sensitive information stored or processed by the application.\nThe issue affects versions of Google Chrome on iOS prior to 152.0.7977.65.\nExploitation requires the attacker to execute a local program on the device, meaning the vulnerability is limited to local threat vectors and does not allow for remote exploitation.\nThe risk implication is centered on the breach of data confidentiality, where sensitive application data could be exposed to unauthorized local entities or processes.\nThe vulnerability highlights a deficiency in the application's local boundary enforcement, potentially allowing an attacker to bypass standard operating system or application-level access controls to read restricted data.",
  "technicalDetails": "The vulnerability stems from improper validation or insufficient access control enforcement within the Chrome on iOS architecture, specifically regarding how the application handles data persistence and interaction with the local file system or inter-process communication (IPC) mechanisms.\nIn the context of mobile application security, Chrome for iOS utilizes the WebKit engine; however, the browser shell and its associated data management services remain subject to application-specific vulnerabilities. The flaw suggests that a local program, executing with sufficient, albeit potentially non-privileged, local access, can interface with insecurely exposed components of the Chrome application.\nThe attack flow requires the adversary to execute malicious or unauthorized code on the targeted iOS device. Upon successful local execution, the malicious program leverages the identified weakness to query, inspect, or exfiltrate sensitive application data that should otherwise be isolated by the iOS sandbox environment or Chrome’s internal security model.\nThe root cause is likely an insufficient restriction on the accessibility of sensitive data structures or temporary files that are handled by the browser process. If the application exposes interfaces that are not adequately protected by standard iOS sandboxing primitives or internal capability checks, a co-located local process can perform unauthorized read operations.\nThe scope of the sensitive information is tied to what Chrome manages locally, which could include browser cookies, cached credentials, browsing history, or form-fill data, depending on the specific component failing to enforce access control. Because the vulnerability is specific to 'local' interaction, the attack does not require network exposure or remote authentication.\nThe post-exploitation impact includes the systematic gathering of sensitive user information, which could be utilized for further malicious activities, such as session hijacking or identity theft, provided the attacker maintains control over the local execution environment on the device."
}
CVE-2026-78981: Chrome iOS Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere