Executive brief
A critical security vulnerability has been identified in Google Chrome for iOS. This flaw allows a remote attacker to execute malicious code on a user's device if they are tricked into visiting a specially crafted website. Such an exploit could lead to the theft of sensitive data, unauthorized access to the device, or a complete compromise of the browser's security.
Technical details
A use-after-free (UAF) vulnerability exists in the iOS-specific implementation of Google Chrome (CWE-416). The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the browser process. This vulnerability was reported by Google and is addressed in version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-04-18: disclosed: Reported by Google internal researchers
- 2026-06-02: patched: Fixed in version 149.0.7827.53
- 2026-06-04: advisory: NVD publication date