CVE-2026-91742: Confused deputy in Google Chrome
Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)
AI Analysis
Technical Summary
CVE-2026-91742 is a confused deputy vulnerability in the PriceTracking feature of Google Chrome on iOS before version 153.0.8010.47. It enables a remote attacker, through social engineering and specially crafted network traffic, to bypass system access controls and gain access to a privileged page within the browser. The vulnerability was publicly disclosed with a medium severity rating by the Chromium security team. The vendor advisory URL is provided but does not explicitly state patch availability in the input data.
Potential Impact
An attacker can bypass system access restrictions to reach a privileged page in Chrome on iOS, potentially exposing sensitive functionality or data accessible only to privileged contexts. The attack requires social engineering and crafted network traffic but does not indicate direct code execution or broader system compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The provided vendor advisory link should be monitored for updates on official fixes or mitigations. Until a patch is confirmed, users should exercise caution with unsolicited network content and social engineering attempts targeting Chrome on iOS.
CVE-2026-91742: Confused deputy in Google Chrome
Description
Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium security severity: Medium)
Affected software
Chrome
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-91742 is a confused deputy vulnerability in the PriceTracking feature of Google Chrome on iOS before version 153.0.8010.47. It enables a remote attacker, through social engineering and specially crafted network traffic, to bypass system access controls and gain access to a privileged page within the browser. The vulnerability was publicly disclosed with a medium severity rating by the Chromium security team. The vendor advisory URL is provided but does not explicitly state patch availability in the input data.
Potential Impact
An attacker can bypass system access restrictions to reach a privileged page in Chrome on iOS, potentially exposing sensitive functionality or data accessible only to privileged contexts. The attack requires social engineering and crafted network traffic but does not indicate direct code execution or broader system compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The provided vendor advisory link should be monitored for updates on official fixes or mitigations. Until a patch is confirmed, users should exercise caution with unsolicited network content and social engineering attempts targeting Chrome on iOS.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-09-14T22:52:56.813Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html","vendor":"Google"}]
Threat ID: 6aa9aed855bf5e2cf55add2f
Added to database: 09/15/2026, 20:47:20 UTC
Last enriched: 09/15/2026, 21:02:06 UTC
Last updated: 09/16/2026, 04:01:23 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.