Description
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-03
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A failed validation of input data in the Transactions Platform component of Google Chrome on iOS permits a remote attacker to deliver a crafted HTML page that can cause the browser to execute code outside its sandbox. The flaw is rooted in an input validation weakness and is classified as CWE‑20. This could allow an attacker to run arbitrarily complex code on the user’s device, potentially compromising data confidentiality, integrity, and availability.

Affected Systems

All Google Chrome installations on iOS devices running a version prior to 152.0.7977.82 are affected. The vulnerability is tied to the Transactions Platform component inherent to Chrome’s rendering engine on iOS.

Risk and Exploitability

Because the flaw allows code execution beyond the browser’s sandbox, the impact is severe. The CVSS score of 9.6 further emphasizes the high severity. The attack requires presenting a malicious HTML page to a user who then browses it. No public exploitation evidence or EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited or no active exploitation at this time. Nonetheless, the potential for arbitrary code execution means the risk remains high for users who may encounter malicious content.

Generated by OpenCVE AI on September 3, 2026 at 21:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on iOS to version 152.0.7977.82 or newer to apply the vendor‑issued fix.
  • Ensure the device’s operating system is updated to the latest iOS release to maintain the strongest sandbox protections.
  • Enable Chrome’s Safe Browsing feature to help detect and block malicious web content.

Generated by OpenCVE AI on September 3, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4776-1 chromium security update
Debian DSA Debian DSA DSA-6484-1 chromium security update
History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple iphone Os
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple iphone Os

Thu, 03 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Google Chrome iOS Remote Code Execution via Crafted HTML

Thu, 03 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 03 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-04T03:56:09.428Z

Reserved: 2026-09-02T21:13:08.098Z

Link: CVE-2026-85047

cve-icon Vulnrichment

Updated: 2026-09-03T19:59:19.704Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-03T20:17:24.690

Modified: 2026-09-08T16:19:18.940

Link: CVE-2026-85047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T22:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation