CVE-2026-85047: Improper input validation in Transactions Platform
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which deployments are affected?
The issue affects Google Chrome on iOS before version 152.0.7977.82. The provided information does not identify affected desktop Chrome versions despite listing a desktop release-note reference.
What does an attacker need to exploit this issue?
An attacker would need to cause a user to load a crafted HTML page remotely. Successful exploitation could potentially allow arbitrary code execution outside the sandbox.
How can I determine whether an installation is affected?
Check the installed Google Chrome for iOS version. Versions earlier than 152.0.7977.82 are affected according to the available data.