Google Chrome for iOS: 25 Vulnerabilities Disclosed Together, Ranging from UI Spoofing to Sandbox Escapes
Key findings • 25 vulnerabilities in Chrome for iOS were disclosed simultaneously on July 30, 2026. • The vulnerabilities range from Low to High severity, impacting UI spoofing, data leakage,…
Key findings
- 25 vulnerabilities in Chrome for iOS were disclosed simultaneously on July 30, 2026.
- The vulnerabilities range from Low to High severity, impacting UI spoofing, data leakage, and sandbox escapes.
- All disclosed issues are fixed in Chrome for iOS version 151.0.7922.72.
- Key vulnerability types include inappropriate implementation, insufficient policy enforcement, and race conditions.
On July 30, 2026, Google released Chrome version 151.0.7922.72, patching a significant batch of 25 vulnerabilities affecting Chrome for iOS. These vulnerabilities, disclosed simultaneously, range in severity from Low to High, with the most critical flaws allowing for UI spoofing, data leaks, and potential sandbox escapes.
The disclosed vulnerabilities can be broadly categorized by their impact:
UI Spoofing and Data Leakage
Several vulnerabilities allow remote attackers to perform UI spoofing or leak sensitive data. These include:
CVE-2026-17822: Race condition leading to UI spoofing.CVE-2026-17826: Inappropriate implementation allowing remote attackers to leak cross-origin data.CVE-2026-17874: Inappropriate implementation leading to UI spoofing.CVE-2026-18013: Inappropriate implementation allowing UI spoofing.CVE-2026-18016: Insufficient policy enforcement resulting in UI spoofing.CVE-2026-17965: Incorrect security UI leading to UI spoofing.CVE-2026-17762: Inappropriate implementation allowing cross-origin data leakage.CVE-2026-18003: Inappropriate implementation leading to UI spoofing.CVE-2026-17839: Inappropriate implementation resulting in UI spoofing.CVE-2026-17828: Inappropriate implementation causing UI spoofing.CVE-2026-17841: Race condition enabling UI spoofing.CVE-2026-17835: Inappropriate implementation leading to UI spoofing.
Navigation and Policy Bypass
Other vulnerabilities focus on bypassing navigation restrictions or security policies:
CVE-2026-17830: Inappropriate implementation allowing bypass of navigation restrictions.CVE-2026-17944: Inappropriate implementation enabling navigation restriction bypass.CVE-2026-17789: Insufficient validation of untrusted input allowing navigation restriction bypass.CVE-2026-17703: Insufficient policy enforcement permitting navigation restriction bypass.CVE-2026-17917: Insufficient policy enforcement allowing bypass of discretionary access control.CVE-2026-17813: Insufficient policy enforcement leading to navigation restriction bypass.
Other Vulnerabilities
The batch also includes vulnerabilities related to UI spoofing via domain spoofing, heap corruption, and potential sandbox escapes:
CVE-2026-17842: Inappropriate implementation allowing bypass of same-origin policy.CVE-2026-17967: Use after free vulnerability potentially exploiting heap corruption.CVE-2026-17838: Incorrect security UI leading to domain spoofing.CVE-2026-17849: Inappropriate implementation allowing Omnibox (URL bar) content spoofing.CVE-2026-18011: Inappropriate implementation allowing local attackers to obtain sensitive information from process memory.CVE-2026-17669: Inappropriate implementation with the potential for a sandbox escape.CVE-2026-17761: Insufficient validation of untrusted input allowing arbitrary script or HTML injection (UXSS).
All 25 vulnerabilities were addressed in Chrome for iOS version 151.0.7922.72. Users are strongly urged to update to this version to mitigate the risks associated with these security flaws. The coordinated disclosure of these vulnerabilities highlights the ongoing efforts to secure the browser environment for mobile users. Vypr Intelligence