External risk intelligence

Chrome for iOS Missing Authorization Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-106323

This vulnerability affects a client-side web browser application (Chrome for iOS) and requires user interaction via social engineering to navigate to a crafted HTML page. As a client-side application rather than a server, edge service, or internet-facing infrastructure component, it does not meet the criteria for public-internet-facing exposure.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in Google Chrome for iOS. This issue could allow a remote attacker, through social engineering, to execute unauthorized code on a user's device via a malicious webpage. The primary concern is to determine if our organization's users or devices are exposed to this risk.

  • Unauthorized code execution via web pages.
  • Requires user interaction; not an infrastructure threat.
  • Confirm relevance and user exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage using social engineering tactics. This webpage would then attempt to exploit a flaw in how Chrome for iOS handles authorization, potentially allowing the attacker to run their own code on the user's device, breaking out of the browser's security sandbox.

  • Requires user interaction via social engineering.
  • Triggered by visiting a crafted HTML page.
  • Risk of arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Chrome for iOS could allow an attacker, through social engineering, to execute arbitrary code outside the browser's sandbox by tricking a user into visiting a malicious webpage. This could impact the confidentiality, integrity, and availability of data and system resources accessible by the app.

  • User data and app functionality could be affected.
  • Via a crafted HTML page and social engineering.
  • Arbitrary code execution outside the sandbox.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Chrome for iOS. Ownership likely falls to teams managing mobile application deployments or end-user device security, with an initial focus on identifying affected users and assessing business criticality. The first practical step involves confirming exposure and then planning remediation, potentially coordinated with the Chrome vendor.

  • Mobile application and device security teams.
  • Verify user exposure and business criticality.
  • Plan vendor-coordinated remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome for iOS?

Google Chrome for iOS is a mobile web browser that provides users with a platform to navigate the internet. It uses the underlying Apple WebKit engine to render websites and includes its own security architecture, known as a sandbox, which is designed to isolate the browser's processes from the rest of the device's operating system and data.

What does CWE-862 mean for CVE-2026-106323?

This vulnerability is classified as CWE-862, or Missing Authorization. In simple terms, this means the software fails to verify if a user or process has permission to perform a specific action. In the context of this CVE, this lack of check allows an attacker to bypass standard security restrictions and execute commands they should not be allowed to run.

How is this vulnerability triggered?

An attacker must successfully use social engineering to trick a user into visiting a specifically crafted HTML page. The bug is not triggered by simply having the application installed or browsing legitimate websites. It requires the user to actively navigate to the malicious page, which then exploits the missing authorization to break out of the browser's protective sandbox.

Is this a major risk for my internal servers?

No. According to Halo Surface Signal, this is a client-side browser issue, not a server-side or infrastructure vulnerability. It does not present a typical internet-facing threat to your backend systems, as the risk is localized to the individual mobile device of a user who has been successfully manipulated into visiting a malicious site.

What steps should I take if I use Chrome for iOS?

Your first priority is to identify devices running older, affected versions of the browser and ensure they are updated to the latest release provided by the vendor. Coordinate with your mobile device management or IT security teams to monitor for software updates and verify that your user base is aware of the risks associated with visiting untrusted or suspicious websites.

References