Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79105

CVE-2026-79105: Google Chrome iOS Auth Bypass Vulnerability

CVE-2026-79105 is an authentication bypass flaw in Google Chrome for iOS that allows attackers to bypass system access restrictions through crafted HTML pages. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-79105 Overview

CVE-2026-79105 is an improper input validation vulnerability [CWE-20] affecting Google Chrome on iOS versions prior to 152.0.7977.65. The flaw resides in the Mobile component and allows a remote attacker to bypass system access restrictions using a crafted HTML page. Exploitation requires user interaction, such as visiting an attacker-controlled web page. Chromium rates the underlying security severity as Low, while the NVD assigns a medium rating based on the network attack surface and integrity impact.

Critical Impact

A crafted HTML page can bypass Chrome for iOS system access restrictions, weakening browser-enforced boundaries and enabling further client-side abuse.

Affected Products

  • Google Chrome for iOS versions prior to 152.0.7977.65
  • Mobile component of Chrome on iOS
  • Downstream Chromium-based browsers on iOS that inherit the affected input validation logic

Discovery Timeline

  • 2026-08-25 - CVE-2026-79105 published to the National Vulnerability Database
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-79105

Vulnerability Analysis

The vulnerability is classified under [CWE-20: Improper Input Validation]. Chrome for iOS fails to correctly validate content processed by its Mobile component when rendering attacker-supplied HTML. An attacker who convinces a user to load a crafted page can bypass system access restrictions that Chrome normally enforces on iOS. The result is limited integrity impact without direct confidentiality or availability loss, but it can serve as a stepping stone in a multi-stage client-side attack chain. The bug is remotely reachable and requires user interaction to trigger.

Root Cause

The root cause is insufficient validation of input handled by Chrome's Mobile code path on iOS. Restriction checks that gate access to protected system-level behaviors do not properly reject malformed or crafted inputs. This allows an adversary to construct HTML content that reaches restricted functionality without satisfying the intended access control conditions. Refer to Chromium Issue #533046298 for the upstream tracking record.

Attack Vector

Exploitation is network-based. A remote attacker hosts or delivers a crafted HTML page, then lures a Chrome for iOS user to open it through phishing, malvertising, or a compromised site. Once the page loads, the malformed input bypasses browser-enforced system access restrictions. No authentication is required, and attack complexity is low, but the attacker depends on user navigation to the malicious resource.

No verified public proof-of-concept code is available. See the Google Chrome Stable Update release notes for vendor context.

Detection Methods for CVE-2026-79105

Indicators of Compromise

  • Chrome for iOS clients reporting a version string earlier than 152.0.7977.65 in mobile device management (MDM) inventory
  • Outbound requests from mobile devices to newly registered or low-reputation domains hosting HTML payloads
  • Anomalous access to iOS system resources or URI handlers immediately following a browser navigation event

Detection Strategies

  • Inventory managed iOS devices and compare installed Chrome versions against the fixed build 152.0.7977.65.
  • Correlate mobile web proxy or DNS telemetry with threat intelligence feeds to flag delivery of crafted HTML pages.
  • Review MDM compliance reports for out-of-date Chrome installations and enforce update policies.

Monitoring Recommendations

  • Ingest mobile browser and MDM telemetry into a central analytics platform to track Chrome version drift over time.
  • Monitor for phishing campaigns targeting mobile users with links designed to be opened in Chrome on iOS.
  • Alert on repeated navigations to suspicious domains from users running vulnerable Chrome versions.

How to Mitigate CVE-2026-79105

Immediate Actions Required

  • Update Google Chrome on iOS to version 152.0.7977.65 or later through the Apple App Store.
  • Push forced Chrome updates via MDM to all managed iOS devices where possible.
  • Communicate the update requirement to end users, especially those handling sensitive data on mobile.

Patch Information

Google addressed CVE-2026-79105 in Chrome for iOS 152.0.7977.65. Details are published in the Google Chrome Stable Update announcement, with tracking in Chromium Issue #533046298. Applying the vendor update is the definitive remediation.

Workarounds

  • Restrict use of Chrome on iOS until devices are confirmed on the patched version, using Safari or another updated browser in the interim.
  • Enforce web filtering policies that block access to untrusted or newly observed domains from mobile devices.
  • Train users to avoid clicking links from unsolicited messages, since exploitation requires user interaction.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.