Junglewise Threat Intelligence

CVE-2026-17669: Google Chrome for iOS sandbox escape in Chrome for iOS

CVE-2026-17669 · Severity: info · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a remote attacker to bypass security restrictions. By convincing a user to visit a specially crafted webpage, an attacker could escape the browser's security sandbox, potentially gaining unauthorized access to the underlying mobile operating system or user data. This could lead to a compromise of the device's integrity and the privacy of information stored on it.

Technical details

An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw is located within the Chrome for iOS component and can be triggered by a remote attacker who provides a specially crafted HTML page. Successful exploitation allows the attacker to perform a sandbox escape, bypassing the isolation boundaries intended to protect the host operating system from malicious web content. This vulnerability was assigned a 'High' severity rating by the Chromium project. Users are advised to update to version 151.0.7922.72 or later to mitigate this risk.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-05-14: disclosed: Reported by Google internal researchers
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats