CVE-2026-17669

Google · Chrome for iOS

An inappropriate implementation in Google Chrome for iOS allows a remote attacker to perform a sandbox escape via a crafted HTML page.

Executive summary

A critical sandbox escape vulnerability in Google Chrome for iOS enables remote attackers to compromise the application environment through malicious web content.

Vulnerability

The vulnerability stems from an inappropriate implementation flaw in the iOS version of Chrome. An unauthenticated remote attacker can leverage this flaw by directing a user to a crafted HTML page to escape the application sandbox.

Business impact

Exploitation of this vulnerability grants an attacker the ability to bypass iOS security boundaries, which could lead to unauthorized access to application data or persistent compromise of the mobile device. The high CVSS score of 9.6 underscores the severity of this risk for mobile users within an enterprise environment.

Remediation

Immediate Action: Update Google Chrome on all iOS devices to version 151.0.7922.72 or later via the App Store.

Proactive Monitoring: Monitor mobile device management (MDM) platforms for devices running outdated browser versions.

Compensating Controls: Enforce mobile security policies that restrict navigation to untrusted or suspicious websites until the update is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Mobile devices are frequent targets for browser-based attacks, and this vulnerability poses a significant risk to mobile security. Administrators must ensure that all iOS users update their Chrome application immediately to neutralize this threat.