Junglewise Threat Intelligence

CVE-2026-11285: Google Chrome for iOS UI spoofing via crafted HTML page

CVE-2026-11285 · Severity: info · CVSS 3.1 · Published 2026-06-05

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to misrepresent or 'spoof' parts of the browser's user interface. This could be used to deceive users into thinking they are interacting with a legitimate site or browser feature when they are actually on a malicious page. This issue primarily impacts the integrity of the user's browsing experience and could be used as a component in phishing attacks.

Technical details

An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 149.0.7827.53. The flaw allows a remote attacker to perform user interface (UI) spoofing via a crafted HTML page. By leveraging this vulnerability, an attacker can manipulate the browser's UI elements to mislead users about the origin or state of the web content. The attack requires the victim to navigate to a malicious URL (User Interaction required). Google has addressed this issue in the stable channel update for version 149.0.7827.53.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-05: disclosed: NVD publication date

References

Related threats