Junglewise Threat Intelligence

CVE-2026-13777: Google Chrome improper input validation in iOSWeb

CVE-2026-13777 · Severity: info · CVSS 9.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS is a popular mobile web browser. A critical security vulnerability in the way the browser handles web content could allow a malicious website to corrupt the application's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to execute unauthorized code on the device, compromising user data and privacy.

Technical details

A critical vulnerability exists in Google Chrome for iOS prior to version 150.0.7871.47 due to improper input validation within the iOSWeb component. The flaw allows for heap corruption when the browser processes a maliciously crafted HTML page. An attacker can trigger this condition remotely without authentication, though user interaction (visiting the malicious site) is required. Successful exploitation could lead to a heap buffer overflow or similar memory corruption, potentially enabling remote code execution (RCE) within the context of the browser process. Google has addressed this issue in the stable channel update 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-14: disclosed: Reported to Google internally
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats