Flaw in Chrome for iOS 7 Reveals Incognito Searches - MacRumors
Skip to Content

Flaw in Chrome for iOS 7 Reveals Incognito Searches

by

Chrome's latest update, which added support for iOS 7, also included a significant flaw that was discovered by design firm Parallax (via TechCrunch). When using the search or address bar in an Incognito window within the app, browsing history will be saved and shared with the standard Google.com browser.


Google’s Incognito mode is designed to keep searches for sensitive information private, but as detailed in the video, searches will be displayed when the standard Google.com browser is accessed. The flaw can be replicated with the following steps:

- Open an Incognito window
- Enter a search term in the address bar and hit enter
- Open a non-Incognito window
- Navigate to Google.com
- Tap the search box on the page to see Incognito searches

TechCrunch contacted Google and learned that there is no fix for the issue, as it is an "unfortunate but unavoidable loophole that comes with building a browser for iOS. The company cites its Incognito support note, which does address the issue.

On Chrome for iOS, due to platform limitation regular and incognito* tabs share HTML5 local storage, which is typically used by sites to store files on your device (client-side caching) or to provide offline functionality. This means the same sites can always access their data in this storage in both regular and incognito* tabs. Incognito* tabs will still keep browsing history and cookies separate from regular tabs, which are cleared once those tabs are closed.

Apple’s default Safari browser does not appear to have the same issue, accurately hiding searches made in Private mode.

Top Rated Comments

165 months ago
Hey everyone, Google here. We screwed something up in our browser. Apple's fault, not it!
Score: 8 Votes (Like | Disagree)
seamer Avatar
165 months ago
I wouldn't be so quick to say "Safari is able to do it." Simply due to the fact Apple doesn't have to follow its own submission process, and their apps can have certain privileges that third-parties cannot.
Score: 6 Votes (Like | Disagree)
165 months ago
I wouldn't be so quick to say "Safari is able to do it." Simply due to the fact Apple doesn't have to follow its own submission process, and their apps can have certain privileges that third-parties cannot.

Indeed, this would seem to be exactly the case, since Apple doesn't let third-party apps restrict HTML5 local storage, which is what Google and other sites use for this search history.

It's also been like this since at least iOS 6, so it's weird that it's suddenly getting all this coverage.
Score: 3 Votes (Like | Disagree)
PracticalMac Avatar
165 months ago


TechCrunch contacted Google and learned that there is no fix for the issue, as it is an "unfortunate but unavoidable loophole that comes with building a browser for iOS. The company cites its Incognito support note (https://support.google.com/chrome/answer/95464?hl=en), which does address the issue. Apple's default Safari browser does not appear to have the same issue, accurately hiding searches made in Private mode.
Someone is dropping the ball.
Score: 3 Votes (Like | Disagree)
bacaramac Avatar
165 months ago
Guess I don't see the big draw to not use iOS Safari. I think it works rather well . Guess it provides benefits to some, but I see no reason to stray from built in apps if you don't have to.
Score: 2 Votes (Like | Disagree)
redscull Avatar
165 months ago
Google is flat out full of bologna. This is their bug, irrefutably.

Sure, it's true that local storage is shared between incognito and normal modes, but it's also trivial to prefix all your storage keys with "incognito-" while reading/writing in incognito mode, and ensuring that normal mode never reads/writes storage keys prefixed with "incognito-".

Would your sensitive data still be on your system? Yeah, chrome would have to periodically clear all "incognito-" prefixed keys' values to resolve that. But at least these sensitive values would never be displayed via the browser. Only a data miner with access to your file system could get at them.

This kind of fix could be performed by a novice engineer. It is an embarrassing bug, not Apple's fault. Not unavoidable.
Score: 2 Votes (Like | Disagree)

Popular Stories

Dynamic Island iPhone 18 Pro Feature

11 Reasons to Wait for the iPhone 18 Pro

Monday May 11, 2026 9:01 am PDT by
We're only four months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a sea change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth noting is that Apple is reportedly planning a major change to its iPhone release cycle this year, adopting a...
iOS 26

iOS 26.5 Features: Everything New in iOS 26.5

Monday May 11, 2026 5:09 pm PDT by
Apple released iOS 26.5 after a few months of beta testing, and while it doesn't have the Siri features we were hoping for since those are being held until iOS 27, there are a handful of useful changes worth knowing about. Subscribe to the MacRumors YouTube channel for more videos. End-to-End Encryption for RCS Support for end-to-end encryption (E2EE) for RCS messages between iPhone and...
General Apps Reddit Feature

Reddit Starts Blocking Mobile Website, Pushing Users to App Instead

Monday May 11, 2026 6:10 am PDT by
Social network Reddit recently began blocking mobile visitors to its website while pushing them to download the official Reddit app, and it's fair to say that the move is not going down well with users. If you visit reddit.com on your iPhone today, you may see a new popup that can't be dismissed, asking you to "get the app to keep using Reddit." A Reddit spokesperson told Ars Technica...