Junglewise Threat Intelligence

CVE-2026-10961: Google Chrome for iOS use after free sandbox escape

CVE-2026-10961 · Severity: info · Published 2026-06-04

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for iOS, the popular web browser used on iPhones and iPads. An attacker who has already gained some control over the browser's internal processes could use this flaw to break out of the security 'sandbox' that normally keeps web content isolated. This could allow a malicious website to gain broader access to the device's data or functions beyond what is typically permitted for a browser.

Technical details

A use-after-free (UAF) vulnerability exists in the Chrome for iOS component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of specially crafted HTML content. An attacker who has already compromised the renderer process can exploit this condition to achieve a sandbox escape, potentially gaining elevated privileges on the iOS device. The vulnerability is addressed in version 149.0.7827.53. Exploitation requires the victim to navigate to a malicious web page.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats