Executive brief
Google Chrome for iOS, a popular mobile web browser, is affected by a security vulnerability that could lead to memory corruption. By tricking a user into visiting a specially crafted website, an attacker could potentially cause the application to crash or execute unauthorized actions. This issue has been addressed in the latest version of the browser, and users are encouraged to update to maintain the security of their mobile browsing experience.
Technical details
A use-after-free (UAF) vulnerability exists in the iOS-specific implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, leading to a use-after-free condition (CWE-416). A remote, unauthenticated attacker can exploit this by inducing a user to load a maliciously crafted HTML page, potentially resulting in heap corruption and arbitrary code execution within the browser's sandbox. The vulnerability is resolved in version 150.0.7871.47.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched