ZeroHour

CVE-2026-87482

PoC mass

Cleartext Transmission Flaw in Google Chrome for iOS HTTPS Upgrades

CVSS 3.1
5.9 medium
EPSS
<1%p7
Published
()
Modified
AI analysis

Google Chrome on iOS contains a cleartext transmission flaw (CWE-319) in the HttpsUpgrades component, the feature that automatically rewrites HTTP navigations to HTTPS. A remote attacker can send crafted network traffic that causes sensitive data on upgraded connections to be transmitted without encryption, allowing the information to be leaked and read in transit; the CVSS vector indicates no integrity or availability impact and no code execution. Only Chrome on iOS builds prior to 153.0.8010.36 are listed as affected. Exploitation has not been reported in the wild; one public issue-tracker reference exists, CISA has not added the flaw to the KEV catalog, and EPSS estimates only a 0.1% probability of exploitation within 30 days.

What to do: Update Google Chrome on iOS to 153.0.8010.36 or later via the App Store and confirm the running version in Chrome's settings; there is no configuration-based mitigation. Until patched, users should avoid entering sensitive credentials or data on untrusted networks such as public Wi-Fi, where an on-path observer is most plausible. Given the Medium severity, lack of in-the-wild exploitation, and iOS-only scope, applying the update within normal patching cycles is reasonable.

Affected
google chromeiOS only: all versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions of Chrome-on-iOS users (Chrome is the dominant third-party browser on a platform with well over 1 billion active devices); affected subset… — Chrome for iOS is widely bundled/installed on Apple's billion-plus active iOS device base, so the unpatched population before the 153.0.8010.36 fix plausibly exceeds 100 million users, though no official install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.