Description
Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑of‑uninitialized‑variable flaw in the Mobile component of Google Chrome on iOS, affecting releases older than 152.0.7977.65. A crafted HTML page can cause the variable to contain unpredictable data, potentially allowing an attacker to execute arbitrary code outside the Chrome sandbox. The flaw falls under CWE‑457 and is rated as critical by Chromium security teams.

Affected Systems

Affected systems are devices running Google Chrome for iOS prior to version 152.0.7977.65.

Risk and Exploitability

Exploitability is high because it requires only a remote attacker to load a malicious web page, which is a typical browsing scenario. The EPSS score is <1%, and the CVSS score of 9.6 indicates a severe risk. The vulnerability is not listed in the CISA KEV catalog, yet the potential for arbitrary code execution warrants immediate remediation.

Generated by OpenCVE AI on August 26, 2026 at 20:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome 152.0.7977.65 or later on all iOS devices
  • If an update is not yet available, temporarily disable Chrome or restrict access to untrusted web content
  • Monitor Google Chrome release notes for additional patches and apply them promptly

Generated by OpenCVE AI on August 26, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use of Uninitialized Variable in Chrome Mobile iOS Allows Potential Remote Code Execution

Wed, 26 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple iphone Os
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple iphone Os

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Use of Uninitialized Variable in Chrome Mobile iOS Allows Potential Remote Code Execution

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-457
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:28.807Z

Reserved: 2026-08-25T06:04:11.684Z

Link: CVE-2026-78935

cve-icon Vulnrichment

Updated: 2026-08-26T15:19:00.995Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:49.270

Modified: 2026-08-27T04:16:59.157

Link: CVE-2026-78935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:45:03Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable