s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-10958

📛 CVE Title

CVE-2026-10958

Description

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Overview

State
PUBLISHED
Assigner (CNA)
Chrome
CVSS severity
high
CVSS score
CVSS 8.8 / 10 8.8 8.8 / 10
CVSS vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Effective score
8.8 / 10 HIGH source: CNA overview
CWE(s)
CWE-416
Reserved
2026-06-04
Published
2026-06-04 23:03 UTC
Last updated
2026-06-05 00:30 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/10xxx/CVE-2026-10958.json
Linked Threat
CVE-2026-10958 — CVE-2026-10958

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-06-04 23:16:58 UTC
NVD last modified
2026-07-22 20:10:00 UTC
NVD CVSS v3.1
CVSS 8.8 / 10 8.8 8.8 / 10 HIGH source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability subscore
2.8 / 10
Impact subscore
5.9 / 10
EPSS score
0.0036 (probability of exploitation in next 30 days)
EPSS percentile
28.68% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26

NVD / KEV / EPSS data refreshed 2026-07-27 12:16 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-34407
Assigner
Chrome
Published
Jun 4, 2026, 11:03:55 PM
Updated
Jun 6, 2026, 3:56:57 AM
EUVD base score (CVSS 3.1)
8.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EUVD-reported EPSS
0.3600
Vendors
Google
Products
Chrome (149.0.7827.53 <149.0.7827.53)
Aliases
GHSA-cr6q-j4hh-gx6r

ENISA description: Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
Google Chrome 149.0.7827.53 (affected)

Affected products — CPE 2.3 (2) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
  • cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (5)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (18)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:cybersecuritynews.com

    Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

    2026-06-08 15:59 UTC
  • web:feedly.com

    CVE Id: CVE-2026-10958 Release Date: 2026 -06-06 Update Date: 2026 -06-06 Description Use after free in Chrome for iOS in Google Chrome on iOS prior to 149..7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page.

    2026-06-08 15:59 UTC
  • web:nvd.nist.gov

    An official website of the United States government Here's how you know

    2026-06-08 15:59 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-06-08 15:59 UTC
  • web:securitricks.com

    CVE CVE-2026-10958 - Score : 8.8 - Source : chrome- cve -admin@google.com - Description : Use after free in Chrome for iOS in Google Chrome on iOS prior to 149..7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) - Tags : chrome- cve -admin@google.com, CWE-416, 2026 -06-04 ...

    2026-06-08 15:59 UTC
  • web:techcommunity.microsoft.com

    We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE - 2026 -42897.

    2026-06-08 15:59 UTC
  • web:vulners.com

    Vulners Cve CVE-2026-10958 CVE-2026-10958 🗓️ 04 Jun 2026 23:03:55 Reported by Chrome Type cve 🔗 www. cve .org

    2026-06-08 15:59 UTC
  • web:www.action1.com

    In this issue: May 2026 Patch Tuesday highlights, vulnerabilities in web browsers, Cisco, Adobe, SAP, Linux, Fortinet, Palo Alto, cPanel, SimpleHelp, nginx-ui, MOVEit ...

    2026-06-08 15:59 UTC
  • web:www.suse.com

    Secure your Linux systems from CVE-2026-10958 . Stay ahead of potential threats with the latest security updates from SUSE.

    2026-06-08 15:59 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-06-08 15:59 UTC
  • web:cybersecuritynews.com

    Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed "RoguePlanet," and confirmed it is actively developing a security patch to address the flaw.

    2026-06-19 02:35 UTC
  • web:guide.sonatype.com

    Technical security analysis for CVE-2026-10958 . CVSS 8.8 severity. View CVSS vectors, CWE classifications, and exploit maturity ratings.

    2026-06-19 02:35 UTC
  • web:tech.yahoo.com

    Microsoft has confirmed an emergency security update as CISA warns that two new Defender zero-days are being exploited by attackers.

    2026-06-19 02:35 UTC
  • web:thehackernews.com

    Microsoft patches 59 vulnerabilities, including six actively exploited zero-days, with CISA mandating urgent federal remediation .

    2026-06-19 02:35 UTC
  • web:www.bleepingcomputer.com

    Today is Microsoft's February 2026 Patch Tuesday with security updates for 58 flaws, including 6 actively exploited and three publicly disclosed zero-day vulnerabilities.

    2026-06-19 02:35 UTC
  • web:www.computerworld.com

    Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...

    2026-06-19 02:35 UTC
  • web:www.malwarebytes.com

    Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.

    2026-06-19 02:35 UTC
  • web:www.microsoft.com

    Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed.

    2026-06-19 02:35 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-10958.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 8.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "REQUIRED",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-10958",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-05T00:25:43.721473Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-05T00:30:58.977Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Chrome",
          "vendor": "Google",
          "versions": [
            {
              "lessThan": "149.0.7827.53",
              "status": "affected",
              "version": "149.0.7827.53",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-416",
              "description": "Use after free",
              "lang": "en"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-06-04T23:03:55.609Z",
        "orgId": "ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28",
        "shortName": "Chrome"
      },
      "references": [
        {
          "url": "https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html"
        },
        {
          "url": "https://issues.chromium.org/issues/507251069"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ebfee0ef-53dd-4cf3-9e2a-08a5bd7a7e28",
    "assignerShortName": "Chrome",
    "cveId": "CVE-2026-10958",
    "datePublished": "2026-06-04T23:03:55.609Z",
    "dateReserved": "2026-06-04T17:06:15.717Z",
    "dateUpdated": "2026-06-05T00:30:58.977Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}