Executive brief
Google Chrome for iOS contains a memory safety vulnerability in its Sync feature that allows attackers to execute arbitrary code outside the browser's security sandbox by tricking users into visiting a malicious webpage. This could lead to complete compromise of user data stored on the device, including passwords, browsing history, and personal information, bypassing the security protections that normally isolate the browser from the rest of the system.
Technical details
A use-after-free vulnerability exists in the Sync component of Google Chrome on iOS versions prior to 152.0.7977.65. The vulnerability can be triggered via a crafted HTML page delivered over the network, requiring user interaction (visiting a malicious webpage). Successful exploitation allows an attacker to execute arbitrary code outside the Chrome sandbox, bypassing the memory protection mechanisms that normally isolate the browser process. The issue was identified as part of Chrome 152's security update and has been patched in version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65 on iOS
Timeline
- 2026-08-25: disclosed: Public disclosure via Chrome Releases blog
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65