Executive brief
Google Chrome for iOS is a popular mobile web browser. A security vulnerability has been identified that could allow a malicious website to cause the browser to crash or potentially execute unauthorized actions by corrupting its memory. This occurs when the browser attempts to use memory that has already been released, typically triggered by visiting a specially crafted web page.
Technical details
A use-after-free (UAF) vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw is categorized under CWE-416 and resides within the Chrome for iOS component. A remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page. Successful exploitation could lead to heap corruption, potentially allowing for arbitrary code execution or a denial-of-service (browser crash) within the context of the application. Google has addressed this issue in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed