Junglewise Threat Intelligence

CVE-2026-13807: Google Chrome for iOS use after free in Import

CVE-2026-13807 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for iOS that could allow a remote attacker to execute unauthorized code on a user's device. To exploit this, an attacker must trick a user into performing specific touch gestures or interactions within the browser while handling a malicious file. Successful exploitation could lead to a full compromise of the browser session and access to sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Import' component of Google Chrome for iOS prior to version 150.0.7871.47. The flaw is triggered when the browser improperly manages memory during the processing of specific files, combined with specific user-driven UI gestures. A remote attacker can exploit this by convincing a user to interact with a specially crafted malicious file, leading to arbitrary code execution (ACE) within the context of the browser. This issue is tracked as CWE-416 and was resolved in the stable channel update for iOS.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-19: disclosed: Reported by Google internal researchers
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats