ZeroHour

CVE-2026-85047

mass

Improper Input Validation in Google Chrome for iOS Enables Out-of-Sandbox Code Execution

CVSS 3.1
9.6 critical
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-85047 is an improper input validation flaw (CWE-20) in the Transactions Platform component of Google Chrome for iOS, present in versions prior to 152.0.7977.82. A remote attacker triggers it by convincing a user to open a crafted HTML page (the CVSS vector requires user interaction). If successful, the attacker can potentially execute arbitrary code outside the browser's sandbox, meaning the code is not contained within Chrome's usual process isolation boundary. All users running Chrome on iOS before 152.0.7977.82 are affected; the issue is rated Medium by Chromium, though its CVSS 3.1 base score is 9.6 (critical). As of now there is no known public proof-of-concept, it is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, although a related Chrome flaw (CVE-2026-85046) in the same release was reported as a zero-day exploited in the wild.

What to do: Update Google Chrome on iOS to 152.0.7977.82 or later via the App Store, and confirm the running version in Chrome's settings before treating devices as patched. Until updated, users should avoid opening links from untrusted sources in Chrome on iOS, since exploitation requires visiting a crafted HTML page. Note that a related Chrome vulnerability (CVE-2026-85046) was exploited in the wild, so patching this release promptly is warranted even though this specific CVE has no confirmed exploitation.

Affected
google chromeiOS versions prior to 152.0.7977.82 (fixed in 152.0.7977.82)
Estimated exposure
masshundreds of millions of users (Chrome for iOS is one of the most widely installed iOS browsers worldwide) — Chrome has a multi-billion-user global install base and maintains a substantial share of iOS browsing, so the vulnerable iOS population is plausibly in the hundreds of millions, though exact counts are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google patched 12 Chrome flaws including in-the-wild V8 zero-day CVE-2026-85046; CISA added it to the KEV catalog.

Google released Chrome 152.0.7977.82/.83 for Windows and Mac (152.0.7977.82 for Linux) fixing 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine being exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 18, 2026. This is Chrome's sixth zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The other 11 fixes include use-after-free, out-of-bounds, race condition and input validation flaws in Skia, WebGL, DevTools, Network, Compositing and other components.