Google Chrome for iOS Inappropriate Implementation Allowing Universal Cross-Site Scripting

Vulnerability

A vulnerability in Google Chrome on iOS, affecting versions prior to 148.0.7778.216, allowed remote attackers to inject arbitrary scripts or HTML, leading to universal cross-site scripting (UXSS). This was achieved by convincing users to perform specific UI gestures on a crafted HTML page.

Impact

Exploitation of this vulnerability allowed for universal cross-site scripting, where injected scripts could be executed in the context of the user's browser.

Remediation

Users can update to Google Chrome version 148.0.7778.216 or later to address this vulnerability.

Added: May 28, 2026, 11:37 PM
Updated: May 28, 2026, 11:37 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
3.8
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.