Doyensec disclosed CVE-2026-13795, an app-launch permission bypass in Chrome for iOS that allowed malicious webpages to abuse Apple Shortcuts deep links. Chrome permitted shortcuts:// and legacy workflow:// URLs to open without the confirmation prompt required for other third-party app schemes.
An attacker could embed a Shortcuts x-callback-url that directed Shortcuts to open sensitive destinations such as tel: or facetime:, bypassing Chrome's user-interaction requirement for the final action. Chromium remediated the issue by requiring an alert before Chrome opens any Shortcuts or Workflow URL, blocking the callback chain unless the user explicitly approves it.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Doyensec documented CVE-2026-13795, an app-launch permission bypass in Chrome for iOS. A malicious webpage could use Apple Shortcuts deep links and callback parameters to reach sensitive schemes such as tel: or facetime: without Chrome applying its final URL user-interaction policy.
Chromium fixed CVE-2026-13795 by requiring an alert before opening any shortcuts:// or legacy workflow:// URL. The initial consent requirement prevents callback chains, including x-success, x-cancel, x-error, and nested Shortcuts URLs, from launching without approval.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.