Junglewise Threat Intelligence

CVE-2026-79217: Google Chrome incorrect authorization in Mobile on iOS

CVE-2026-79217 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome, Apple Iphone Os. Vendors: Google, Apple.

Executive brief

Google Chrome on iOS contains an authorization flaw that could allow an attacker to bypass system-level access restrictions. An attacker can exploit this vulnerability by crafting a malicious HTML page and tricking a user into visiting it, potentially gaining unauthorized access to restricted functionality or data on the device.

Technical details

This vulnerability is an incorrect authorization flaw in the Mobile component of Google Chrome on iOS prior to version 152.0.7977.65. The vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page, requiring user interaction to visit the malicious page. The attack is delivered over the network and does not require prior authentication. Google has patched this issue in Chrome 152.0.7977.65 and later releases on iOS.

Affected products

  • Google Chrome prior to 152.0.7977.65 on iOS

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats