Executive brief
Google Chrome is a widely-used web browser deployed across billions of devices including iPhones and iPads. This vulnerability allows an attacker to bypass operating system access restrictions by tricking a user into visiting a malicious webpage, potentially giving unauthorized access to sensitive system resources or user data on the device.
Technical details
This vulnerability is an improper input validation flaw in the Mobile component of Google Chrome on iOS. An unauthenticated remote attacker can exploit this via a crafted HTML page to bypass system access restrictions. The attack requires user interaction (visiting a malicious webpage) and operates over the network. The vulnerability was patched in Chrome version 152.0.7977.65 for iOS and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on iOS
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched