Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious actor to execute unauthorized scripts or display fake content within the browser. This occurs when a user is tricked into scanning a specially crafted QR code and performing specific touch gestures. An exploit could lead to the theft of sensitive information or the display of deceptive information to the user.
Technical details
A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome for iOS due to insufficient validation of untrusted input when processing QR codes. A remote attacker can exploit this by convincing a user to scan a malicious QR code and engage in specific UI gestures. This flaw allows the attacker to bypass the Same-Origin Policy (SOP) and inject arbitrary scripts or HTML into the context of any website. The issue is addressed in version 149.0.7827.53.
Affected products
- Google Chrome for iOS prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-04: disclosed: CVE published to NVD