Junglewise Threat Intelligence

CVE-2026-13850: Google Chrome for iOS improper input validation code execution

CVE-2026-13850 · Severity: info · CVSS 7.8 · Published 2026-06-30

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

Google Chrome for iOS is a popular web browser used on Apple mobile devices. A security flaw in versions prior to 150.0.7871.47 could allow a malicious file to execute unauthorized code on a user's device. While the impact is limited by the application's security sandbox, it could still lead to unauthorized actions or data access within the browser environment.

Technical details

An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw stems from insufficient validation of untrusted input when processing files. A local attacker can exploit this by convincing a user to open a specially crafted malicious file, leading to arbitrary code execution within the browser's sandbox environment. Google has addressed this issue in the stable channel update 150.0.7871.47 for iOS.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats