CVE-2026-78935

Google · Chrome

A use of an uninitialized variable in Google Chrome on iOS allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

A critical vulnerability in Google Chrome for iOS allows unauthenticated remote attackers to achieve arbitrary code execution via crafted web content.

Vulnerability

The flaw is caused by the use of an uninitialized variable (CWE-457) in the Mobile component of Chrome for iOS, which can be triggered by an unauthenticated remote attacker through a malicious HTML page.

Business impact

The ability for an attacker to execute arbitrary code outside the application sandbox represents a total compromise of the affected device. Given the CVSS score of 9.6, this vulnerability poses an extreme risk to organizational data confidentiality, integrity, and availability, potentially leading to full device takeover or lateral movement within a corporate network.

Remediation

Immediate Action: Update Google Chrome on all iOS devices to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Security teams should review mobile device management logs for unusual browser activity and restrict access to untrusted web domains where possible.

Compensating Controls: While a Web Application Firewall cannot directly patch the client side, maintaining up-to-date mobile security policies and endpoint protection can help detect anomalous process behavior resulting from exploitation.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical nature of this remote code execution vulnerability and the potential for sandbox escape, organizations must prioritize the deployment of the vendor-provided update. Ensure all mobile users are notified of the requirement to update Chrome through the App Store to maintain the security of corporate data accessed on mobile devices.

More Google CVEs

Sources