Description
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an insufficient validation of untrusted input in Chrome for iOS's renderer component. A remote attacker who can gain control of the renderer process could deliver a malicious HTML page that exploits this defect to escape the browser's sandbox, potentially allowing execution of code with elevated privileges. The weakness is classified as CWE-20, Unvalidated Input.

Affected Systems

Google Chrome for iOS releases older than 151.0.7922.72 are vulnerable; the defect is present in the Chrome browser app provided by Google for iOS devices.

Risk and Exploitability

With a CVSS score of 9.6 this issue is severe. The EPSS score is less than 1%, indicating a very low but non-zero likelihood of exploitation at the time of analysis. It is not listed in the CISA KEV catalog. An attacker would likely need to compromise the renderer process first, which could happen by visiting a malicious web page in Chrome for iOS. Once the renderer is compromised, a crafted HTML page could be used to escape the sandbox and execute higher-privilege code.

Generated by OpenCVE AI on August 4, 2026 at 12:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome for iOS to version 151.0.7922.72 or newer; the patch removes the unvalidated input handling flaw.
  • Ensure devices run the latest iOS update that includes the updated Chrome components, as security updates may be bundled with the OS.
  • In enterprise settings, restrict loading of arbitrary or untrusted HTML content in Chrome for iOS, or apply stringent content-security policies to limit the impact of potential renderer compromises.

Generated by OpenCVE AI on August 4, 2026 at 12:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Tue, 04 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome for iOS Enables Sandbox Escape via Crafted HTML Page

Fri, 31 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome for iOS Enables Sandbox Escape via Crafted HTML Page

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T15:05:34.790Z

Reserved: 2026-07-27T23:34:22.227Z

Link: CVE-2026-17684

cve-icon Vulnrichment

Updated: 2026-07-30T15:05:23.652Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:30.660

Modified: 2026-08-03T12:15:20.990

Link: CVE-2026-17684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:30:09Z

Weaknesses
  • CWE-20

    Improper Input Validation