Low chrome Logic Error 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactIncorrect security UI in Chrome for iOS
DescriptionIncorrect security UI in Chrome for iOS
ComponentChrome for iOS
Bug ClassLogic Error
Tracker514068611
Fix commitd9b6c6d45e4e (chromium/src) +27/-3
CISA KEVNot listed
CreditedGoogle
Disclosed2026-06-30

Changed Functions

FunctionChangeNotes
if
ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_coordinator.mm
modified

Files Changed

  • ios/chrome/browser/unit_conversion/ui_bundled/BUILD.gn
  • ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_coordinator.mm
From d9b6c6d45e4e843b4275d8efeb7be8647af90811 Mon Sep 17 00:00:00 2001
From: Elmehdi Rahmaoui <[email protected]>
Date: Thu, 21 May 2026 03:42:53 -0700
Subject: [PATCH] [ios] Secure unit conversion popover anchoring on iPad

This CL addresses a potential vulnerability where attacker-controlled
webpages could anchor unit conversion popovers to privileged browser
UI components (e.g., the omnibox) by passing extreme coordinates.
To resolve this, we:
1. Update the popover's sourceView to be the active WebState's view
   instead of the full browser view (baseViewController.view).
2. Clamp the popover's positioning coordinates within the active
   WebState's view bounds using std::clamp.

Bug: 514068611
Change-Id: Ifc03925d46bb9bd6ae13d86449a4be9d9ad37ff1
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7857773
Reviewed-by: Mark Cogan <[email protected]>
Commit-Queue: Elmehdi Rahmaoui <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1634162}
---

diff --git a/ios/chrome/browser/unit_conversion/ui_bundled/BUILD.gn b/ios/chrome/browser/unit_conversion/ui_bundled/BUILD.gn
index 489fca7..135d0c5 100644
--- a/ios/chrome/browser/unit_conversion/ui_bundled/BUILD.gn
+++ b/ios/chrome/browser/unit_conversion/ui_bundled/BUILD.gn
@@ -17,6 +17,7 @@
     "//ios/chrome/browser/shared/coordinator/chrome_coordinator",
     "//ios/chrome/browser/shared/model/browser",
     "//ios/chrome/browser/shared/model/prefs:pref_names",
+    "//ios/chrome/browser/shared/model/web_state_list",
     "//ios/chrome/browser/shared/public/commands",
     "//ios/chrome/browser/unit_conversion/model",
     "//ios/chrome/browser/unit_conversion/model:unit_conversion_factory",
@@ -25,6 +26,7 @@
     "//ios/chrome/common/ui/confirmation_alert",
     "//ios/chrome/common/ui/util",
     "//ios/public/provider/chrome/browser/unit_conversion:unit_conversion_api",
+    "//ios/web/public",
     "//ui/base",
   ]
 }
diff --git a/ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_coordinator.mm b/ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_coordinator.mm
index d09dfa95..7c563dc 100644
--- a/ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_coordinator.mm
+++ b/ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_coordinator.mm
@@ -4,13 +4,17 @@
 
 #import "ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_coordinator.h"
 
+#import <algorithm>
+
 #import "ios/chrome/browser/shared/model/browser/browser.h"
+#import "ios/chrome/browser/shared/model/web_state_list/web_state_list.h"
 #import "ios/chrome/browser/shared/public/commands/command_dispatcher.h"
 #import "ios/chrome/browser/shared/public/commands/scene_commands.h"
 #import "ios/chrome/browser/unit_conversion/model/unit_conversion_service.h"
 #import "ios/chrome/browser/unit_conversion/model/unit_conversion_service_factory.h"
 #import "ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_mediator.h"
 #import "ios/chrome/browser/unit_conversion/ui_bundled/unit_conversion_view_controller.h"
+#import "ios/web/public/web_state.h"
 
 namespace {
 
@@ -107,7 +111,6 @@
 
 // Presents the UnitConversionCoordinator's view controller and adapt the
 // presentation based on the device (popover for ipad, half sheet for iphone)
-
 - (void)presentUnitConversionViewController {
   UINavigationController* navigationController = [[UINavigationController alloc]
       initWithRootViewController:_viewController];
@@ -115,9 +118,28 @@
   UIPopoverPresentationController* popover =
       navigationController.popoverPresentationController;
   popover.delegate = _viewController;
-  popover.sourceView = self.baseViewController.view;
+  web::WebState* activeWebState =
+      self.browser->GetWebStateList()->GetActiveWebState();
+  UIView* sourceView = activeWebState ? activeWebState->GetView() : nil;
+
+  popover.sourceView = sourceView ?: self.baseViewController.view;
+
+  CGPoint location = _location;
+  if (sourceView) {
+    // Convert the location from the browser view's coordinate system to the
+    // WebState view's coordinate system, and clamp it to the bounds of the
+    // WebState view.
+    location = [self.baseViewController.view convertPoint:_location
+                                                   toView:sourceView];
+    CGRect bounds = sourceView.bounds;
+    location.x =
+        std::clamp(location.x, CGRectGetMinX(bounds), CGRectGetMaxX(bounds));
+    location.y =
+        std::clamp(location.y, CGRectGetMinY(bounds), CGRectGetMaxY(bounds));
+  }
+
   popover.sourceRect =
-      CGRectMake(_location.x, _location.y, kPopOverSourceRectWidth,
+      CGRectMake(location.x, location.y, kPopOverSourceRectWidth,
                  kPopOverSourceRectHeight);
   popover.permittedArrowDirections =
       UIPopoverArrowDirectionUp | UIPopoverArrowDirectionDown;
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.