Junglewise Threat Intelligence

CVE-2026-17724: Google Chrome for iOS race condition in UXSS

CVE-2026-17724 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A race condition in Google Chrome for iOS could allow a remote attacker to perform Universal Cross-Site Scripting (UXSS). By tricking a user into visiting a specially crafted webpage, an attacker could inject and execute malicious scripts or HTML within the context of any website the user visits. This could lead to the theft of sensitive information, such as login credentials or session cookies, across different web domains.

Technical details

A race condition vulnerability (CWE-362) exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw occurs during the handling of shared resources, which can be exploited by a remote attacker using a crafted HTML page to achieve Universal Cross-Site Scripting (UXSS). Successful exploitation allows the attacker to bypass the Same-Origin Policy (SOP) and execute arbitrary JavaScript or HTML in the context of any site loaded by the browser. This issue was addressed in the stable channel update to version 151.0.7922.72.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released
  • 2026-07-30: disclosed: NVD publication date

References

Related threats