CVE-2026-91742: Google Chrome on iOS vulnerability
Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (iOS)to a version that resolves this vulnerability.Fixed in 153.0.8010.47
Event History
Frequently Asked Questions
Which Chrome installations are affected?
Google Chrome on iOS versions prior to 153.0.8010.47 are affected. The provided information does not indicate that other platforms are affected.
What does an attacker need to exploit this issue?
The attacker must use crafted network traffic and leverage social engineering. The issue may allow them to bypass system access restrictions and reach a privileged page.
Is there a workaround if updating is not immediately possible?
No workaround or mitigation is provided in the available information. Updating Chrome on iOS to 153.0.8010.47 or later is the stated version boundary for remediation.