Executive brief
Google Chrome for iOS is a mobile web browser used for accessing the internet on Apple devices. A security vulnerability has been identified that could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to execute unauthorized actions on the device.
Technical details
A use-after-free (UAF) vulnerability exists in the iOS-specific implementation of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated, typically during the processing of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to heap corruption. This can result in a stable browser crash (Denial of Service) or potentially arbitrary code execution within the sandbox context of the browser. The issue is resolved in version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel.
- 2026-06-04: disclosed: CVE published to NVD.