Executive brief
Google Chrome for iOS is a mobile web browser used to access the internet. A security vulnerability was found that could allow a malicious website to run unauthorized code on a user's device if the user performs specific touch gestures or interactions. While the impact is limited by the browser's security sandbox, it could still lead to unauthorized access to browser data or further exploitation of the device.
Technical details
An uninitialized use vulnerability (CWE-457) exists in Google Chrome for iOS prior to version 148.0.7778.216. The flaw is triggered when a remote attacker convinces a user to perform specific UI gestures while visiting a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code within the context of the browser's sandbox. This vulnerability is specific to the iOS implementation of the browser. Google has addressed this issue in the stable channel update 148.0.7778.216.
Affected products
- Google Chrome for iOS Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: CVE published to NVD