ZeroHour

CVE-2026-78935

mass

Uninitialized Variable in Google Chrome for iOS Allows Out-of-Sandbox Code Execution

CVSS 3.1
9.6 critical
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-78935 is a use of uninitialized variable (CWE-457) in the Mobile component of Google Chrome on iOS, rated Critical by the Chromium team. An attacker triggers the flaw by persuading a user to open a crafted HTML page in the browser, which requires user interaction but no privileges. Successful exploitation allows a remote attacker to potentially execute arbitrary code outside the browser sandbox, giving code execution at a higher privilege level on the device than the sandboxed renderer. Only Chrome on iOS is indicated; users of Chrome for iOS on versions prior to 152.0.7977.65 are affected. As of now there is no listing in CISA's KEV, no known public proof-of-concept, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days, so exploitation has not been confirmed.

What to do: Update Chrome on iOS to version 152.0.7977.65 or later via the App Store on all managed and personal iOS devices. Note this advisory applies only to Chrome on iOS; desktop Chrome is not indicated, but verify your mobile fleet since iOS endpoints often fall outside standard patch tooling. Given the critical severity and web-triggered attack vector, prioritize this update in your next patch cycle even though no in-the-wild exploitation has been reported.

Affected
Google Chrome for iOS (Mobile component)all versions prior to 152.0.7977.65
Estimated exposure
masshundreds of millions of users plausibly affected (Chrome for iOS has hundreds of millions of users) — Chrome is the most widely used third-party browser on iOS, with an estimated user base in the high hundreds of millions across the >1-billion-device iOS install base, so essentially all Chrome-on-iOS users below the fixed version are in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-457
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.