CVE-2026-9963: Uninitialized Use in iOS in Google Chrome on iOS prior to 148
Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
Uninitialized memory use in Google Chrome on iOS (versions prior to 148.0.7778.216) allows a remote attacker to execute arbitrary code inside the browser sandbox. The attacker must reach the victim over the network and convince them to perform specific UI gestures on a crafted HTML page; no credentials are required. Successful exploitation gives the attacker code execution within the Chrome sandbox, with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection for CVE-2026-9963 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built iOS app container images. Coverage extends to any image layering a Chrome on iOS dependency at a version below 148.0.7778.216.
AvailableHarborGuard scores this CVE at 7.5 HIGH (CVSS v3.1) and can weight that score against each customer environment's compliance policy to adjust priority accordingly. Triage findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim's device over the network, delivering a crafted HTML page from a remote origin.
- AuthenticationNot required
No account or credential is needed; the attacker only needs the victim to visit a malicious page.
- Victim interactionRequired
The victim must be socially engineered into performing specific UI gestures on the crafted page, making phishing or deceptive UI a necessary part of the attack chain.
- Attack complexityDetail
Attack complexity is high, meaning the attacker must account for timing, specific gesture sequences, or other environmental conditions that cannot be fully controlled, reducing exploit reliability.
Blast Radius
- Attacker achieves arbitrary code execution within the Chrome sandbox on the victim's iOS device.
- Confidentiality impact is high: sandbox-accessible data such as browsing history, cached credentials, and session tokens can be read.
- Integrity impact is high: the attacker can modify data and state within the sandbox, including stored site data and local app storage accessible to Chrome.
- Availability impact is high: the attacker can crash or destabilize the Chrome process, disrupting browser availability on the device.
How HarborGuard Handles This
Available on HarborGuard: detection for this CVE fires within minutes of ingestion and surfaces any image carrying a vulnerable Chrome on iOS version below 148.0.7778.216. For customers with auto-remediation enabled, HarborGuard makes a rebuilt image at the patched version available, runs regression tests, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuild is queued and the owning team is notified with full CVSS context and affected image inventory. Because this vulnerability requires victim interaction via crafted UI gestures, network-policy controls that restrict which origins users can reach from managed environments serve as a useful compensating control until the patched image is deployed.
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H