CVE-2026-7361

8.8

Google · Chrome

A use after free vulnerability in Google Chrome for iOS allows a remote attacker to trigger heap corruption via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome for iOS could allow a remote attacker to achieve code execution or system compromise.

Vulnerability

The vulnerability is a use after free flaw (CWE-416) within the browser engine, which can be triggered by an unauthenticated remote attacker through a specially crafted HTML page. Successful exploitation leads to heap corruption, which may result in arbitrary code execution or a denial of service.

Business impact

The potential for heap corruption and subsequent code execution poses a severe risk to organizational data and device integrity. Given the high CVSS score of 8.8, this vulnerability represents a significant threat to mobile device fleets, potentially enabling unauthorized access to sensitive browser-stored credentials or local files.

Remediation

Immediate Action: Update Google Chrome on all iOS devices to the latest patched version available in the App Store to ensure the vulnerable code is removed.

Proactive Monitoring: Monitor device logs for unusual browser crashes or unexpected behavior that may indicate an attempt to exploit memory corruption vulnerabilities.

Compensating Controls: Use mobile device management (MDM) policies to enforce browser updates and restrict the opening of untrusted or suspicious web links on managed mobile assets.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

The severity of this memory corruption flaw necessitates immediate attention from security teams managing mobile device environments. Administrators should prioritize the deployment of the vendor-provided update to all iOS devices to prevent potential remote exploitation.

More Google CVEs

Sources