top of page
perceptive_background_267k.jpg

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the re…

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 19:11:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17684 is a high-severity vulnerability in Google Chrome for iOS affecting versions prior to 151.0.7922.72. The flaw stems from insufficient validation of untrusted input in the Chrome for iOS component. A remote attacker who has already compromised the renderer process could exploit this vulnerability to perform a sandbox escape. The attack vector requires a crafted HTML page to trigger the escape. This vulnerability is classified as High severity by the Chromium security team. The fix was included in the stable channel update for Chrome 151.0.7922.72. Users on iOS are advised to update to the latest version immediately. The issue is currently awaiting full analysis on NVD.

Technical details

Mitigation steps:

Affected products:

Google Chrome for iOS
Chrome 151.0.7922.72

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page