Junglewise Threat Intelligence

CVE-2026-9971: Google Chrome UXSS in iOS UI implementation

CVE-2026-9971 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to execute unauthorized scripts in the context of other websites. This occurs when a user is tricked into performing specific touch gestures on a specially crafted webpage. If exploited, an attacker could potentially steal sensitive information, such as login session tokens or personal data, from other sites the user has open.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the iOS-specific UI handling. A remote attacker can exploit this by convincing a user to perform specific UI gestures on a malicious HTML page. This bypasses Same-Origin Policy (SOP) protections, allowing the injection of arbitrary scripts or HTML into different origins. The vulnerability is fixed in version 148.0.7778.216. Chromium developers have classified this as High severity.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats