Junglewise Threat Intelligence

CVE-2026-13915: Google Chrome for iOS use after free in UI gestures

CVE-2026-13915 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

Google Chrome for iOS is a popular mobile web browser. A vulnerability in older versions could allow a malicious website to cause the browser to crash or behave unexpectedly if a user performs specific touch gestures on a specially crafted webpage. This could lead to service instability or potential memory corruption on the user's device.

Technical details

A use-after-free (UAF) vulnerability exists in Google Chrome for iOS (versions prior to 150.0.7871.47) within the browser's UI handling components. The flaw is triggered when a user interacts with a specially crafted HTML page using specific UI gestures, leading to the reuse of memory that has already been freed. This root cause can result in heap corruption. An attacker could leverage this to cause a denial-of-service (browser crash) or potentially achieve arbitrary code execution within the sandbox. The vulnerability is mitigated by the requirement for specific user interaction (UI gestures). The issue was addressed in version 150.0.7871.47.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats