Chromium: Critical Skia Flaw and iOS Vulnerabilities Disclosed Together
Google patched six Chromium vulnerabilities disclosed July 1-3, 2026, including a critical Skia heap buffer overflow and multiple flaws in Chrome for iOS.

Key findings
- Critical heap buffer overflow in Skia (CVE-2026-14427) disclosed on July 3, 2026.
- Six Chromium vulnerabilities disclosed between July 1-3, 2026, affecting Chrome versions prior to 150.0.7871.46/47.
- Multiple high and medium severity flaws impact Chrome for iOS, including data leaks and UI spoofing.
- Patches available in Google Chrome 150.0.7871.46 and 150.0.7871.47.
On July 1, 2026, Google addressed a significant batch of vulnerabilities affecting Chromium, with a critical heap buffer overflow in Skia disclosed on July 3, 2026. The vulnerabilities, impacting Google Chrome prior to version 150.0.7871.46 and 150.0.7871.47, span a range of severity levels from Low to Critical. This disclosure event highlights ongoing security challenges in complex browser components.
Several vulnerabilities were specifically identified in Chrome for iOS. These include CVE-2026-13946, a medium-severity flaw related to ScriptInjections that could lead to cross-origin data leaks via a crafted HTML page. CVE-2026-13808, a high-severity issue involving insufficient data validation in Chrome for iOS, could allow a local attacker with physical access to obtain sensitive information from process memory. Additionally, CVE-2026-14066 and CVE-2026-13847, both rated low and high respectively, stem from insufficient validation of untrusted input in Chrome for iOS, potentially allowing remote attackers to bypass navigation restrictions or leak cross-origin data through crafted HTML pages. CVE-2026-13907, another medium-severity vulnerability in iOSWeb, could enable UI spoofing through specific user interactions with a crafted HTML page.
The most severe vulnerability disclosed, CVE-2026-14427, is a critical heap buffer overflow in the Skia graphics component. This flaw, discovered on July 3, 2026, could allow a compromised renderer process to potentially escape the sandbox via a crafted HTML page. This type of vulnerability is particularly concerning as it can lead to broader system compromise.
All disclosed vulnerabilities, with the exception of CVE-2026-14427 which was fixed in version 150.0.7871.46, were addressed in Google Chrome version 150.0.7871.47. Users are strongly advised to update to the latest available version to mitigate these risks. The batch of vulnerabilities underscores the continuous need for vigilance in browser security, as attackers may leverage various techniques, including crafted HTML pages and UI manipulation, to exploit weaknesses.
This coordinated disclosure event, with most vulnerabilities published on July 1, 2026, and one critical flaw on July 3, 2026, emphasizes the dynamic nature of cybersecurity. Users of Chromium-based browsers, particularly Google Chrome on iOS, should remain aware of these security updates and apply them promptly to protect against potential exploits. The range of vulnerabilities, from UI spoofing to sandbox escapes, highlights the diverse attack surface within modern web browsers.