Sceawere

Vulnerability Detail

CVE-2026-85047UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome Transactions Platform Arbitrary Execution

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
3h ago
Vendor
Google
Product
Chrome
Attack Type
Improper input validation
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-03T20:17:24.690Z",
  "pubdate": "2026-09-03T20:17:24.690Z",
  "executiveSummary": "This vulnerability involves an improper input validation flaw within the Transactions Platform component of Google Chrome on iOS. A remote attacker can leverage this flaw by directing a victim to a specially crafted HTML page, potentially facilitating arbitrary code execution outside the browser's security sandbox.\nThe vulnerability is classified as a medium-severity security issue. Successful exploitation grants an attacker the ability to bypass the browser's sandbox isolation, which is a critical boundary designed to protect the underlying operating system from malicious web content.\nThe impact is significant, as it enables an attacker to move beyond the context of the browser and potentially execute arbitrary code on the host iOS device. Affected versions include all instances of Google Chrome on iOS prior to 152.0.7977.82. Exploitation requires user interaction, specifically the victim navigating to the malicious HTML content.\nGiven the nature of the flaw, the risk implication involves a total compromise of the application's integrity and potential escalation to the device level, depending on the success of the sandbox escape. Organizations and individual users are urged to update to the specified version to remediate the underlying logic error in the input handling mechanism.",
  "technicalDetails": "The vulnerability resides within the input validation logic of the Transactions Platform component in Google Chrome for iOS. The root cause is a failure to properly sanitize or validate input data processed by this platform when rendering or interpreting data from a remote web resource. By providing crafted input, an attacker can trigger memory corruption or logic errors that facilitate an escape from the constrained browser sandbox environment.\nThe attack flow begins when a user navigates to a malicious HTML page controlled by the attacker. This page contains a payload specifically designed to interface with the vulnerable Transactions Platform API. Because the component does not adequately validate the structure or constraints of the input, the malicious data is processed in a manner that leads to unexpected behavior during the transaction orchestration process.\nThe sandbox escape occurs because the Transactions Platform process possesses sufficient privilege to interact with system-level APIs or IPC mechanisms that, when abused via improper input, allow the transition of execution flow from the browser context to the broader operating system environment. By injecting crafted instructions, an attacker can transition from the web content sandbox into an unauthorized execution state.\nTechnically, the vulnerability suggests a lack of strict typing or boundary checking during the deserialization or processing of transaction-related data structures. Once the initial processing threshold is breached, the attacker can leverage memory corruption primitives to overwrite pointers or function addresses, facilitating arbitrary code execution (ACE). Since the target is the Transactions Platform, the exploit likely circumvents standard security constraints typically enforced by the browser's core engine.\nThe exploitation does not require prior authentication or elevated privileges from the user, as the attack is delivered entirely through the rendering of a web page. However, it requires a specific sequence of operations that interface with the Transactions Platform. Post-exploitation, the attacker achieves code execution outside the sandbox, which effectively compromises the browser's security posture and potentially exposes user data or system resources on the iOS device, depending on the specific capabilities and entitlements held by the compromised platform process."
}
CVE-2026-85047: Chrome Transactions Platform Arbitrary Execution (CRITICAL Severity, CVSS: 9.6) - Sceawere