Executive brief
A vulnerability in the media handling component of Google Chrome for iOS could allow a remote attacker to access sensitive information from the device's memory. This issue occurs when a user visits a specially crafted website, provided the attacker has already gained a foothold in the browser's rendering process. Exploitation could lead to the exposure of private data or assist in further compromising the user's device.
Technical details
An inappropriate implementation vulnerability exists in the Media component of Google Chrome for iOS. The flaw allows a remote attacker to perform an out-of-bounds (OOB) memory read. To exploit this, an attacker must first compromise the renderer process and then entice a user to visit a malicious HTML page. This could allow the attacker to read sensitive information from the browser's memory space. The issue is addressed in version 148.0.7778.168.
Affected products
- Google Chrome for iOS prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Stable channel update released for desktop and iOS versions.
- 2026-05-14: disclosed: CVE published to NVD.