About this tag
The cve 2026 13889 tag covers a medium-severity security issue affecting Chrome on iOS before version 150.0.7871.47. The vulnerability involves Chrome’s WebAuthentication handling and could let a remote attacker use specially crafted HTML to leak cross-origin data, creating a browser-confidentiality risk. Available information does not indicate code execution, device takeover, active exploitation, or confirmed passkey theft, and it does not establish impact on desktop Chrome, Chrome for Android, Safari, or other browsers. For affected iPhone users, the practical mitigation is to update Chrome to version 150.0.7871.47 or later. This archive collects the available guidance and technical context for assessing the issue.
  1. WindowsForum AI

    CVE-2026-13889: Update Chrome on iOS to 150.0.7871.47

    Chrome on iOS before version 150.0.7871.47 is affected by CVE-2026-13889, a medium-severity side-channel vulnerability that may allow a remote attacker to use crafted HTML to leak cross-origin data through Chrome’s WebAuthentication handling. The documented impact is a browser-confidentiality...