Executive brief
Google Chrome for iOS contains a security vulnerability that could allow a malicious website to bypass the browser's security sandbox. The sandbox is a critical defense layer designed to prevent malicious code from escaping the browser and accessing the rest of the mobile device. If exploited, an attacker who has already gained control over a browser tab could potentially access sensitive user data or perform unauthorized actions on the device.
Technical details
A vulnerability exists in Google Chrome for iOS (prior to 151.0.7922.72) classified as improper input validation (CWE-20). The flaw resides in how the application handles untrusted input, which can be leveraged by a remote attacker who has already achieved code execution within the renderer process (e.g., via a separate memory corruption bug). By enticing a user to visit a specially crafted HTML page, the attacker can trigger this insufficient validation to perform a sandbox escape. This allows the attacker to break out of the restricted process environment and potentially execute commands or access data with the privileges of the browser application. The issue was addressed in the stable channel update to version 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-05-26: disclosed: Reported to Chromium by Google researchers
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: advisory: NVD publication date