Junglewise Threat Intelligence

CVE-2026-10952: Google Chrome for iOS use after free

CVE-2026-10952 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS is a mobile web browser used for accessing the internet on Apple devices. A security vulnerability has been identified that could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to execute unauthorized actions on the device.

Technical details

A use-after-free (UAF) vulnerability exists in the iOS-specific implementation of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated, typically during the processing of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to heap corruption. This can result in a stable browser crash (Denial of Service) or potentially arbitrary code execution within the sandbox context of the browser. The issue is resolved in version 149.0.7827.53.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats