Junglewise Threat Intelligence

CVE-2026-85047: Google Chrome improper input validation in Transactions Platform on iOS

CVE-2026-85047 · Severity: critical · CVSS 9.6 · Published 2026-09-03

Technologies: Google Chrome, Apple Iphone Os. Vendors: Google, Apple.

Executive brief

Google Chrome on iOS contains a flaw in its Transactions Platform component that fails to properly validate user-supplied input. An attacker could exploit this vulnerability by sending a specially crafted webpage to a user, potentially executing malicious code outside the browser's security sandbox and compromising the device. This could lead to unauthorized access to sensitive data or control of the device.

Technical details

A improper input validation vulnerability exists in the Transactions Platform component of Google Chrome on iOS prior to version 152.0.7977.82. The vulnerability allows a remote attacker to execute arbitrary code outside the browser sandbox by crafting a malicious HTML page. The attack requires user interaction (visiting a malicious website) but does not require authentication. An attacker could achieve sandbox escape and arbitrary code execution on the affected iOS device. The vulnerability has been patched in Chrome version 152.0.7977.82 and later.

Affected products

  • Google Chrome prior to 152.0.7977.82 on iOS

Timeline

  • 2026-09-03: disclosed: Published in Chrome security update
  • 2026-09-03: patched: Fixed in Chrome 152.0.7977.82 for iOS

References

Related threats