CVE-2026-79039

Google · Chrome

A use after free vulnerability in Google Chrome for iOS allows a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic.

Executive summary

A high-severity use after free vulnerability in Google Chrome for iOS poses a critical risk of remote code execution, necessitating an immediate update to the latest version.

Vulnerability

The flaw is a use after free vulnerability (CWE-416) within the mobile implementation of the browser. An unauthenticated remote attacker can trigger this condition through maliciously crafted network traffic to achieve arbitrary code execution outside the browser sandbox.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute code with the privileges of the application, potentially leading to full system compromise or sensitive data exfiltration. With a CVSS score of 8.1, this vulnerability represents a significant threat to organizational security, as it bypasses critical sandbox protections designed to isolate browser processes from the underlying operating system.

Remediation

Immediate Action: Update Google Chrome on all iOS devices to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor network traffic for unusual patterns or anomalous payloads directed at iOS devices that might indicate attempts to exploit browser-based vulnerabilities.

Compensating Controls: Ensure that mobile device management (MDM) policies enforce timely application updates and restrict the installation of unauthorized applications that could be used as an entry point for lateral movement.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the capability for remote code execution and the severity of a sandbox escape, organizations must prioritize the deployment of the provided update to all mobile endpoints. Failure to patch leaves devices vulnerable to sophisticated network-based attacks that can bypass standard browser security controls, significantly increasing the risk of device compromise.

More Google CVEs

Sources