Sceawere

Vulnerability Detail

CVE-2026-79105UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome iOS Input Validation Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Improper input validation
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-25T21:18:05.777Z",
  "pubdate": "2026-08-25T21:18:05.777Z",
  "executiveSummary": "This vulnerability involves an improper input validation flaw within the Mobile version of Google Chrome on iOS, specifically identified prior to version 152.0.7977.65.\nThe vulnerability manifests as a security bypass, allowing a remote attacker to circumvent established system access restrictions.\nThe flaw is categorized as an improper input validation issue, which could be leveraged by a malicious actor via a crafted HTML page to perform unauthorized actions outside the intended sandbox constraints.\nAlthough the Chromium security severity is rated as Low, the ability for a remote attacker to bypass iOS system-level restrictions presents a significant security risk to the integrity of the browser's security model.\nExploitation requires the user to interact with or navigate to a specially crafted HTML page provided by the attacker.\nThe vulnerability effectively undermines the browser's enforcement of security boundaries, potentially granting unauthorized access to restricted system resources or data that should otherwise be protected from web-based content.",
  "technicalDetails": "The root cause of this vulnerability lies in insufficient input sanitization and validation logic within the browser's handling of web content on the iOS platform. Mobile browsers utilize platform-specific engines to render web pages, and the integration layer between the web engine and the host operating system's security primitives is where this failure occurs.\nIn this instance, the Chromium component responsible for parsing HTML and managing platform-specific access controls failed to properly validate or normalize inputs provided through malicious web content. When the browser processes a crafted HTML page, the underlying validation mechanisms fail to detect or block malicious payload structures designed to trigger prohibited system operations.\nThe attack flow begins when a user is directed to a malicious HTML page. Upon rendering, the crafted payload leverages the improper validation flaw to send unauthorized commands or requests to the iOS operating system's interfaces. Because the browser fails to enforce adequate restrictions on the input, the malicious instructions are accepted by the system-level components, allowing the attacker to bypass access controls that would typically confine the browser's operations within a restricted sandbox environment.\nThis bypass allows for unintended interaction with system-level resources or data repositories that the browser is permitted to access under normal circumstances but should not expose to the content within the HTML page. The exploitation does not require prior authentication or elevated privileges from the user; it relies purely on the browser's willingness to process and execute the provided HTML content without adequate filtering.\nThe vulnerable component is the input processing and validation pipeline within Google Chrome for iOS, which is tasked with sanitizing data flows between the rendering engine and the iOS host environment. All versions of Google Chrome for iOS preceding 152.0.7977.65 are susceptible to this flaw.\nPost-exploitation, an attacker may achieve unauthorized access to sensitive system features or stored browser data, effectively breaking the confinement policies mandated by the browser's architecture. The scope of impact is limited by the iOS sandbox, but the bypass allows the attacker to operate outside the intended browser-specific security policies."
}
CVE-2026-79105: Chrome iOS Input Validation Bypass (MEDIUM Severity, CVSS: 4.3) - Sceawere