Executive brief
A security flaw in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's address bar (Omnibox). This could lead users to believe they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent page designed to steal login credentials or other sensitive information. Users are advised to update their mobile browser to the latest version to prevent these types of phishing attacks.
Technical details
A URL spoofing vulnerability exists in Google Chrome for iOS prior to version 150.0.7871.47 due to an inappropriate implementation in the Omnibox component. By enticing a user to visit a specially crafted HTML page, a remote attacker can manipulate the address bar to display a fraudulent URL while the browser renders malicious content. This bypasses a primary security indicator used by users to verify the authenticity of a website. The vulnerability is classified as 'High' severity by Chromium developers. A fix is available in version 150.0.7871.47 and later.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched