Description
Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome on iOS suffers a use‑after‑free flaw in the Sync component that allows a remote attacker to supply a crafted HTML page and potentially execute code outside the browser sandbox. The flaw is a classic memory management bug (CWE‑416) and can lead to full device compromise if executed successfully. The description emphasizes that the impact is limited to code execution but carries significant severity in terms of confidentiality, integrity, and availability of the affected device.

Affected Systems

All users of Google Chrome on iOS with a build prior to 152.0.7977.65 are affected. The bug was present in the Sync feature of the browser and does not apply to non‑iOS platforms or later releases.

Risk and Exploitability

The CVSS score is not provided and the EPSS score is unavailable, but the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a crafted web page delivered over HTTP/HTTPS. Because the flaw allows execution outside the sandbox, it is a high‑impact vulnerability, yet the overall risk is tempered by the lack of widespread exploitation evidence at this time.

Generated by OpenCVE AI on August 25, 2026 at 22:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later.
  • If an update cannot be applied immediately, disable the Sync feature to eliminate the code path that leads to the use‑after‑free.
  • Monitor official Google release notes and security advisories for any new workarounds or special instructions.

Generated by OpenCVE AI on August 25, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title Use After Free Exploit in Chrome iOS Sync Allows Remote Code Execution
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-25T20:11:00.195Z

Reserved: 2026-08-25T06:05:16.953Z

Link: CVE-2026-78964

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:52.507

Modified: 2026-08-25T21:17:52.507

Link: CVE-2026-78964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:30:17Z

Weaknesses