← Terug naar overzicht

CVE-2026-85047 describes an improper input validation vulnerability in the Transactions Platform component of Google Chrome on iOS. The flaw affects versions prior to 152.0.7977.82 and allows a remote attacker to potentially execute arbitrary code outside the sandbox. Exploitation is achieved via a specially crafted HTML page, requiring no user authentication beyond visiting the malicious page. The Chromium project has rated this vulnerability as Medium severity. Google has addressed the issue in Chrome 152.0.7977.82 for iOS. The vulnerability was disclosed via the NVD and referenced in the Chrome stable channel update blog post. Users are advised to update their Chrome browser on iOS to the latest available version immediately.

Affected products

  • Google Chrome on iOS (prior to 152.0.7977.82)

Related CVE's

  • CVE-2026-85047

Categories

  • Mobile & IoT
  • Web Technologies
  • Zero-Day Vulnerabilities