Executive brief
Google Chrome for iOS contains a use-of-uninitialized-variable vulnerability in its Mobile component that allows attackers to execute arbitrary code outside the browser's security sandbox. An attacker can trigger this vulnerability by crafting a malicious HTML page and tricking a user into viewing it, potentially compromising user data and device security. This affects Chrome versions prior to 152.0.7977.65 on iOS.
Technical details
The vulnerability is a use-of-uninitialized-variable defect in Chrome's Mobile component (Chromium bug 522082472) that allows remote code execution outside the security sandbox. The attack vector is network-based, requiring no user authentication but requiring user interaction (opening a crafted HTML page). An attacker who successfully exploits this can achieve arbitrary code execution with implications beyond the sandbox boundary. The vulnerability has been patched in Chrome 152.0.7977.65 (released August 25, 2026 for iOS), and no public exploit was known at the time of advisory publication.
Affected products
- Google Chrome prior to 152.0.7977.65 on iOS
Timeline
- 2026-08-25: disclosed: Publicly disclosed via Chrome Releases blog and NVD
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for iOS