Junglewise Threat Intelligence

CVE-2026-11202: Google Chrome for iOS sandbox escape via crafted HTML page

CVE-2026-11202 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to bypass the browser's security sandbox. The sandbox is a critical security layer designed to prevent malicious code from escaping the browser and accessing the rest of the mobile device. If exploited, an attacker could potentially gain unauthorized access to sensitive data or perform actions outside the restricted browser environment.

Technical details

A sandbox escape vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the browser's core components. The flaw is categorized as improper input validation (CWE-20). A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation could allow the attacker to bypass the security boundaries of the browser process, potentially leading to broader system access or data compromise on the iOS device. The issue is resolved in version 149.0.7827.53.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats