Executive brief
Google Chrome on iOS contains a use-after-free vulnerability in its Mobile component that could allow remote attackers to execute arbitrary code outside the sandbox when processing crafted network traffic. This vulnerability could lead to complete compromise of the affected device, potentially exposing user data and enabling installation of malware.
Technical details
This vulnerability is a use-after-free condition in the Mobile component of Google Chrome on iOS prior to version 152.0.7977.65. The vulnerability can be exploited remotely via crafted network traffic without requiring user authentication or special privileges. A successful exploit allows an attacker to execute arbitrary code outside the Chrome sandbox boundary, potentially gaining full access to the system and user data. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on iOS
Timeline
- 2026-08-25: disclosed: Public disclosure via Chrome Releases blog
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65