Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-85047: Chrome on iOS may let malicious page run code
CVE-2026-85047 · published today
Summary
Versions of the Chrome browser for iPhone and iPad before 152.0.7977.82 could be tricked by a specially crafted web page to run code outside the browser's protected area. This could allow an attacker to take actions on the device without your permission. Install the latest Chrome update to protect yourself.
What to do
- Update google chrome to version 152.0.7977.82 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| chrome | < 152.0.7977.82 |
Original advisory text
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafte...
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Severity
9.6
Critical
Type
CWE-20Improper Input Validation
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta