Description
Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a malicious file. (Chromium security severity: High)
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use‑after‑free in Chrome’s import feature on iOS allows a remote attacker to execute arbitrary code if a user opens a crafted file and performs specific UI gestures. The flaw is limited to versions before 150.0.7871.47 and provides an attacker the ability to run code on the device, compromising confidentiality, integrity, and availability.

Affected Systems

Google Chrome on iOS, versions older than 150.0.7871.47.

Risk and Exploitability

The vulnerability is rated as High severity in Chromium, but the EPSS score is not available, and the attack vector is not listed in KEV. Because it requires a victim to be tricked into opening a malicious file and performing UI gestures, the exploitation probability is likely low to moderate unless successful social engineering is achieved. However, if exploited, an attacker can execute arbitrary code with the device’s privileges.

Generated by OpenCVE AI on July 1, 2026 at 00:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or newer.
  • Instruct users to avoid opening unknown files or files from untrusted sources and refrain from performing unfamiliar UI gestures.
  • Disable the import feature or restrict it via Chrome settings or company policy until the patch is applied.

Generated by OpenCVE AI on July 1, 2026 at 00:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome iOS Import Allows Remote Code Execution via Malicious File

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a malicious file. (Chromium security severity: High)
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-30T22:37:40.380Z

Reserved: 2026-06-29T23:03:22.568Z

Link: CVE-2026-13807

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T01:00:14Z

Weaknesses