Description
Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypass system access restrictions via crafted HTML page
Action: Patch
AI Analysis

Impact

Improper input validation in the Mobile component of Google Chrome on iOS before version 152.0.7977.65 enabled a remote attacker to bypass system access restrictions by serving a crafted HTML. The flaw could be leveraged to gain unauthorized system privileges through a web‑based attack vector. The weakness is identified as CWE-20, reflecting an input validation error.

Affected Systems

Google Chrome for iOS users whose browsers run versions earlier than 152.0.7977.65. All devices using the affected Chrome builds are at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, an EPSS of <1%, and is not listed in the CISA KEV catalog. Based on the description, the attacker must be able to deliver a crafted HTML page to the target iOS device, suggesting a remote exploitation path that requires user interaction or a malicious webpage. While the lack of severity metrics makes precise risk quantification difficult, the widespread use of Chrome on iOS and the remote nature of the attack raise concerns about potential impact.

Generated by OpenCVE AI on August 26, 2026 at 21:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all iOS devices to Chrome version 152.0.7977.65 or later to eliminate the input‑validation flaw.
  • If an immediate update is not possible, enforce device‑management restrictions that block the vulnerable Chrome version or prevent the user from accessing the affected browser until the patch is applied.
  • Regularly review Google Chrome release notes and security advisories to stay informed about new patches or related vulnerabilities.

Generated by OpenCVE AI on August 26, 2026 at 21:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple iphone Os
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple iphone Os

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Bypass System Access Restrictions via Crafted HTML in Google Chrome on iOS

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Bypass System Access Restrictions via Crafted HTML in Google Chrome on iOS

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:04:10.753Z

Reserved: 2026-08-25T06:09:26.267Z

Link: CVE-2026-79105

cve-icon Vulnrichment

Updated: 2026-08-26T19:04:06.247Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:05.777

Modified: 2026-08-28T14:38:08.293

Link: CVE-2026-79105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation