Junglewise Threat Intelligence

CVE-2026-17761: Google Chrome for iOS UXSS via improper input validation

CVE-2026-17761 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a remote attacker to inject malicious scripts or content into web pages. This occurs when the browser fails to properly check data received over the network. If exploited, an attacker could potentially steal sensitive information or perform unauthorized actions on behalf of the user within their browser session.

Technical details

An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw allows a remote attacker to perform Universal Cross-Site Scripting (UXSS) by injecting arbitrary scripts or HTML through malicious network traffic. This bypasses the Same-Origin Policy, potentially allowing the attacker to execute code in the context of any website the user visits. The vulnerability is triggered by insufficient validation of untrusted input within the Chrome for iOS component. Users are advised to update to version 151.0.7922.72 or later to mitigate this risk.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: disclosed: CVE published and update announced
  • 2026-07-29: patched: Fixed in version 151.0.7922.72

References

Related threats