Chromium fixed CVE-2026-95355, a privilege-escalation flaw in iOS Chromium's CRWWKNavigationHandler. An attacker that had already achieved renderer code execution could forge navigation to the bundled error_page_loaded.html file, making the browser treat attacker-controlled content as a trusted local error page.
The trusted error-page state could then allow navigation to a privileged chrome:// WebUI URL and expose native WebUI bindings to the compromised renderer, enabling a sandbox escape. Chromium addressed the issue on August 21, 2026, in commit bb617c8b09d43ed4d617d0c2b6769899324c9ee8 by validating error-page navigations against browser-side state and restricting navigations from committed error pages; the fix was targeted for M154 release notes.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The iOS Chromium privilege-escalation issue was registered as CVE-2026-95355. Chromium also updated its vulnerability release-notes target to 0-M154.
Chromium committed bb617c8b09d43ed4d617d0c2b6769899324c9ee8, “ios: Validate error page navigations in CRWWKNavigationHandler,” and marked the issue fixed. The change restricts local error-page navigation to browser-initiated, safe history/reload, or securely managed session-restoration cases.
A proposed fix based on pending NavigationContext state was not accepted after testing showed it still allowed a webpage to load an error page directly.
Initial reproduction from ordinary webpage JavaScript failed because WebKit blocked local file loads. Chromium developers later confirmed that a compromised renderer could bypass the renderer-side local-resource checks and reach the vulnerable native navigation handling.
An experimental security project identified a potential confused-deputy flaw in Chromium for iOS error-page navigation handling. The flaw could let an already compromised renderer forge a bundled error-page navigation and ultimately obtain privileged WebUI bindings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.