Executive brief
A vulnerability in the sign-in component of Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by mimicking legitimate browser prompts. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
An inappropriate implementation in the Signin component of Google Chrome on iOS allowed a remote attacker to perform user interface (UI) spoofing. By enticing a user to visit a specially crafted HTML page, an attacker could manipulate or overlay browser UI elements. This is classified as a CWE-20 (Improper Input Validation) issue. The vulnerability is fixed in version 149.0.7827.53 and later. Exploitation requires user interaction (visiting a malicious site) but no special privileges.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 stable channel update released
- 2026-06-05: disclosed: CVE published to NVD