External risk intelligence

Sync Use After Free in Google Chrome on iOS

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-78964

This vulnerability exists in the Google Chrome browser on iOS. While web browsers are commonly used to access the internet, this specific issue requires a user to navigate to a crafted HTML page. It is not an internet-facing service, gateway, or edge appliance that is passively reachable, making public internet exposure a possibility contingent on user interaction rather than by design.

Use After Free

Google Chrome

before 152.0.7977.65

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Google Chrome on iOS could allow a remote attacker to execute arbitrary code outside the sandbox by visiting a malicious webpage. While the Chromium security severity is rated as Low, the CVSS base score is Critical, indicating a high potential impact if exploited. The main concern at this time is confirming relevance and exposure due to the user interaction required for exploitation.

  • Code execution risk in Chrome on iOS.
  • Critical score requires awareness for potential impact.
  • Confirm relevance and assess exposure across iOS devices.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious web page, which then exploits a flaw in Chrome's Sync feature on iOS. This could allow the attacker to execute code outside the browser's protected environment.

  • Requires user interaction with a malicious page.
  • Triggers a use-after-free vulnerability in Sync.
  • Enables code execution outside the sandbox.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome on iOS, when supported by the advisory, could allow a remote attacker to execute arbitrary code outside the browser's sandbox by tricking a user into visiting a malicious HTML page.

  • Arbitrary code execution on the user's device.
  • Requires user to visit a crafted HTML page.
  • Compromised user device and potential data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Google Chrome on iOS requires a user to visit a malicious HTML page. The first step is to identify all iOS devices with affected Chrome versions, confirm reachability through user browsing habits, and then coordinate with mobile device management and application owners to plan remediation.

  • Identify affected iOS devices and Chrome instances.
  • Verify user exposure to malicious web content.
  • Coordinate app updates with MDM.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome on iOS?

Google Chrome on iOS is a web browser application that allows users to access internet content on iPhones and iPads. It uses the underlying Chromium engine to render web pages and manage features like browsing history, bookmarks, and account synchronization, known as Sync.

What does a use-after-free vulnerability mean in CVE-2026-78964?

This vulnerability is classified as CWE-416, which is a memory management error. It occurs when a program continues to use a memory address after it has been cleared or deleted. In this specific case, an attacker can manipulate this state to trick the browser into executing unauthorized code.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by enticing a user to navigate to a specifically crafted HTML page. Simply having the browser installed or running in the background does not trigger the vulnerability; it requires active user interaction with malicious web content to exploit the Sync component.

Is my device at risk based on Halo Surface Signal?

According to Halo Surface Signal, this vulnerability is not an internet-facing service or appliance that can be attacked passively. Instead, risk depends on user behavior. Devices are only at risk if a user actively navigates to a malicious site, making the actual exposure contingent on browsing habits.

How should I respond to this Chrome security update?

The primary response is to ensure Chrome on all iOS devices is updated to version 152.0.7977.65 or later. You should identify affected devices within your environment and coordinate through your mobile device management systems to ensure the browser software is patched.

References