Improper Input Validation in Google Chrome for iOS Enables Out-of-Sandbox Code Execution
AI analysis
CVE-2026-85047 is an improper input validation flaw (CWE-20) in the Transactions Platform component of Google Chrome for iOS, present in versions prior to 152.0.7977.82. A remote attacker triggers it by convincing a user to open a crafted HTML page (the CVSS vector requires user interaction). If successful, the attacker can potentially execute arbitrary code outside the browser's sandbox, meaning the code is not contained within Chrome's usual process isolation boundary. All users running Chrome on iOS before 152.0.7977.82 are affected; the issue is rated Medium by Chromium, though its CVSS 3.1 base score is 9.6 (critical). As of now there is no known public proof-of-concept, it is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, although a related Chrome flaw (CVE-2026-85046) in the same release was reported as a zero-day exploited in the wild.
What to do: Update Google Chrome on iOS to 152.0.7977.82 or later via the App Store, and confirm the running version in Chrome's settings before treating devices as patched. Until updated, users should avoid opening links from untrusted sources in Chrome on iOS, since exploitation requires visiting a crafted HTML page. Note that a related Chrome vulnerability (CVE-2026-85046) was exploited in the wild, so patching this release promptly is warranted even though this specific CVE has no confirmed exploitation.
Affected
| google chrome | iOS versions prior to 152.0.7977.82 (fixed in 152.0.7977.82) |
Estimated exposure
masshundreds of millions of users (Chrome for iOS is one of the most widely installed iOS browsers worldwide) — Chrome has a multi-billion-user global install base and maintains a substantial share of iOS browsing, so the vulnerable iOS population is plausibly in the hundreds of millions, though exact counts are unknown.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.