Junglewise Threat Intelligence

CVE-2026-14068: Google Chrome UXSS in Omnibox for iOS

CVE-2026-14068 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS is a mobile web browser. A vulnerability in the address bar (Omnibox) could allow a malicious website to trick a user into performing specific touch gestures that result in the execution of unauthorized scripts. This could lead to the theft of sensitive information or the performance of actions on behalf of the user on other websites.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in the Omnibox component of Google Chrome for iOS prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that fails to properly isolate execution environments when specific user interface gestures are performed. A remote attacker can exploit this by convincing a user to visit a specially crafted HTML page and engage in specific UI interactions. Successful exploitation allows the attacker to inject arbitrary scripts or HTML into the context of other websites, bypassing the Same-Origin Policy. The issue is addressed in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats