Junglewise Threat Intelligence

CVE-2026-13843: Google Chrome for iOS sandbox escape via improper input validation

CVE-2026-13843 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for iOS that could allow a remote attacker to bypass the browser's security sandbox. By convincing a user to visit a specially crafted website, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying mobile operating system. This could lead to unauthorized access to sensitive device data or the execution of malicious code outside of the browser's restricted environment.

Technical details

An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw resides in how the application handles untrusted input within the renderer process. A remote attacker who has successfully compromised the renderer process can exploit this weakness by tricking a user into loading a malicious HTML page. Successful exploitation allows the attacker to perform a sandbox escape, potentially leading to arbitrary code execution on the host iOS system. Google has addressed this issue in the stable channel update 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats