Junglewise Threat Intelligence

CVE-2026-10896: Google Chrome for iOS use after free remote code execution

CVE-2026-10896 · Severity: info · CVSS 9.8 · Published 2026-06-04

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for iOS. This flaw allows a remote attacker to execute malicious code on a user's device if the user visits a specially crafted website. Such an exploit could lead to the theft of sensitive data, unauthorized access to the device, or a complete compromise of the browser's security. Users are advised to update to the latest version of Chrome immediately to mitigate this risk.

Technical details

A use-after-free (UAF) vulnerability exists in the iOS-specific implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, allowing a remote attacker to leverage a crafted HTML page to corrupt memory. This can lead to arbitrary code execution (ACE) within the context of the browser process. The vulnerability was reported by Google internally and is addressed in version 149.0.7827.53. While the CVSS score was not provided in the advisory, Chromium has assigned it a 'Critical' severity rating, which typically corresponds to high-impact remote code execution.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-05-15: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in version 149.0.7827.53
  • 2026-06-04: advisory

References

Related threats