CVE-2026-17684
9.6Google · Chrome
A sandbox escape vulnerability exists in Google Chrome for iOS, where insufficient input validation allows an attacker to compromise the renderer process via a crafted HTML page.
Executive summary
A critical sandbox escape vulnerability in Google Chrome for iOS could allow a remote attacker to gain significant control over the affected device through malicious web content.
Vulnerability
The flaw is categorized as insufficient validation of untrusted input (CWE-20). A remote attacker can trigger this vulnerability by enticing a user to navigate to a specifically crafted HTML page, leading to a sandbox escape after the renderer process has been compromised.
Business impact
The potential impact of this vulnerability is severe, as it allows for a complete sandbox escape, potentially leading to unauthorized access to user data, execution of arbitrary code, or complete system compromise. With a CVSS score of 9.6, this vulnerability represents a critical risk to organizational mobile security, necessitating immediate attention to prevent potential data breaches or device takeover.
Remediation
Immediate Action: Update Google Chrome for iOS to version 151.0.7922.72 or later immediately to apply the vendor-provided security fixes.
Proactive Monitoring: Monitor mobile device management (MDM) logs for outdated browser versions and review network traffic for suspicious redirects or anomalous patterns associated with mobile browsing.
Compensating Controls: While standard WAFs may have limited efficacy against client-side browser exploits, enforcing mobile application security policies through MDM can restrict the impact of compromised browser sessions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this sandbox escape, organizations must prioritize the deployment of the latest Chrome update across all managed iOS devices. Failure to patch allows for a high-impact entry point into mobile environments, and administrators should ensure that all users are prompted to update their browser software immediately to mitigate this exposure.