Junglewise Threat Intelligence

CVE-2026-11205: Google Chrome for iOS UXSS via crafted QR code

CVE-2026-11205 · Severity: info · CVSS 6.1 · Published 2026-06-04

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious actor to execute unauthorized scripts or display fake content within the browser. This occurs when a user is tricked into scanning a specially crafted QR code and performing specific touch gestures. An exploit could lead to the theft of sensitive information or the display of deceptive information to the user.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome for iOS due to insufficient validation of untrusted input when processing QR codes. A remote attacker can exploit this by convincing a user to scan a malicious QR code and engage in specific UI gestures. This flaw allows the attacker to bypass the Same-Origin Policy (SOP) and inject arbitrary scripts or HTML into the context of any website. The issue is addressed in version 149.0.7827.53.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats