


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the re…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 18:03:11
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17684 is a high-severity vulnerability in Google Chrome for iOS affecting versions prior to 151.0.7922.72. The flaw stems from insufficient validation of untrusted input in the Chrome for iOS component. A remote attacker who has already compromised the renderer process could exploit this vulnerability to perform a sandbox escape. The attack vector requires a crafted HTML page to trigger the exploit. This vulnerability is classified as High severity by the Chromium security team. The fix was included in the stable channel update released in July 2026. Users are advised to update to Chrome 151.0.7922.72 or later on iOS devices to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Google Chrome for iOS
Google Chrome prior to 151.0.7922.72
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17684
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/516894682
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
