Junglewise Threat Intelligence

CVE-2026-9956: Google Chrome for iOS use after free in UI gestures

CVE-2026-9956 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for iOS could allow a remote attacker to execute unauthorized code on a user's device. To exploit this, an attacker would need to trick a user into visiting a malicious website and performing specific touch or interface gestures. Successful exploitation could lead to a full compromise of the browser session and potential access to sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in the iOS implementation of Google Chrome (CWE-416). The flaw is triggered when a user is convinced to perform specific UI gestures while viewing a specially crafted HTML page. This memory corruption issue allows a remote attacker to achieve arbitrary code execution within the context of the browser process. The vulnerability was addressed in version 148.0.7778.216. While the advisory lists 'info' severity, Chromium's internal assessment classifies this as High severity.

Affected products

  • Google Chrome for iOS prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in version 148.0.7778.216
  • 2026-05-28: disclosed

References

Related threats