Executive brief
A security vulnerability exists in the Google Chrome browser for iOS devices. By tricking a user into visiting a specially crafted website, an attacker could potentially bypass security protections (the 'sandbox') that normally keep web content isolated from the rest of the device. This could lead to unauthorized access to sensitive data or broader control over the application.
Technical details
A use-after-free (UAF) vulnerability exists in the WebMIDI implementation of Google Chrome for iOS. The flaw is triggered when the browser incorrectly manages memory for MIDI device interfaces, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to execute arbitrary code or achieve a sandbox escape. The vulnerability was addressed in version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 stable channel update released
- 2026-06-04: disclosed: NVD publication date