CVE-2026-78935
massUninitialized Variable in Google Chrome for iOS Allows Out-of-Sandbox Code Execution
CVE-2026-78935 is a use of uninitialized variable (CWE-457) in the Mobile component of Google Chrome on iOS, rated Critical by the Chromium team. An attacker triggers the flaw by persuading a user to open a crafted HTML page in the browser, which requires user interaction but no privileges. Successful exploitation allows a remote attacker to potentially execute arbitrary code outside the browser sandbox, giving code execution at a higher privilege level on the device than the sandboxed renderer. Only Chrome on iOS is indicated; users of Chrome for iOS on versions prior to 152.0.7977.65 are affected. As of now there is no listing in CISA's KEV, no known public proof-of-concept, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days, so exploitation has not been confirmed.
What to do: Update Chrome on iOS to version 152.0.7977.65 or later via the App Store on all managed and personal iOS devices. Note this advisory applies only to Chrome on iOS; desktop Chrome is not indicated, but verify your mobile fleet since iOS endpoints often fall outside standard patch tooling. Given the critical severity and web-triggered attack vector, prioritize this update in your next patch cycle even though no in-the-wild exploitation has been reported.
| Google Chrome for iOS (Mobile component) | all versions prior to 152.0.7977.65 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-457
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.