Description
Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw is a missing authorization check in Google Chrome for iOS. A remote attacker can send a victim a crafted HTML page that, if the victim visits it, may execute arbitrary code outside the browser sandbox. This represents a high‑severity problem per Chromium’s own ratings, exposing the user to full system compromise if the vulnerability is exercised.

Affected Systems

Google Chrome for iOS versions prior to 155.0.8059.39 are vulnerable. All users running those builds on iOS devices are at risk until they upgrade to the patched release.

Risk and Exploitability

The vulnerability is exploitable when a user is tricked into opening a malicious web page, indicating a social‑engineering attack vector. No EPSS score is publicly available, and the exploit is not listed in CISA’s KEV catalog, but the CVSS score of 9.6 and the potential for arbitrary code execution suggest a significant risk if not patched.

Generated by OpenCVE AI on October 7, 2026 at 02:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install Chrome version 155.0.8059.39 or later on all iOS devices
  • If an update cannot be installed immediately, uninstall Chrome and avoid using it until a patched version is available
  • Ensure the device is set to receive automatic updates and keep Chrome within the latest stable channel

Generated by OpenCVE AI on October 7, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Chrome for iOS Enables Remote Code Execution via Crafted HTML

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:56:09.413Z

Reserved: 2026-10-06T16:35:18.667Z

Link: CVE-2026-106323

cve-icon Vulnrichment

Updated: 2026-10-06T20:50:11.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:18:00.567

Modified: 2026-10-07T13:41:49.420

Link: CVE-2026-106323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses