Executive brief
Google Chrome for iOS is a popular web browser used on Apple mobile devices. A security flaw in versions prior to 150.0.7871.47 could allow a malicious file to execute unauthorized code on a user's device. While the impact is limited by the application's security sandbox, it could still lead to unauthorized actions or data access within the browser environment.
Technical details
An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw stems from insufficient validation of untrusted input when processing files. A local attacker can exploit this by convincing a user to open a specially crafted malicious file, leading to arbitrary code execution within the browser's sandbox environment. Google has addressed this issue in the stable channel update 150.0.7871.47 for iOS.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched