CVE-2026-87482
PoC massCleartext Transmission Flaw in Google Chrome for iOS HTTPS Upgrades
Google Chrome on iOS contains a cleartext transmission flaw (CWE-319) in the HttpsUpgrades component, the feature that automatically rewrites HTTP navigations to HTTPS. A remote attacker can send crafted network traffic that causes sensitive data on upgraded connections to be transmitted without encryption, allowing the information to be leaked and read in transit; the CVSS vector indicates no integrity or availability impact and no code execution. Only Chrome on iOS builds prior to 153.0.8010.36 are listed as affected. Exploitation has not been reported in the wild; one public issue-tracker reference exists, CISA has not added the flaw to the KEV catalog, and EPSS estimates only a 0.1% probability of exploitation within 30 days.
What to do: Update Google Chrome on iOS to 153.0.8010.36 or later via the App Store and confirm the running version in Chrome's settings; there is no configuration-based mitigation. Until patched, users should avoid entering sensitive credentials or data on untrusted networks such as public Wi-Fi, where an on-path observer is most plausible. Given the Medium severity, lack of in-the-wild exploitation, and iOS-only scope, applying the update within normal patching cycles is reasonable.
| google chrome | iOS only: all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-319
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.