Junglewise Threat Intelligence

CVE-2026-13902: Google Chrome UI spoofing in Chrome for iOS

CVE-2026-13902 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This type of flaw is typically used in phishing attacks to trick users into believing they are on a legitimate website or interacting with a trusted browser prompt. An attacker could use this to steal sensitive information like login credentials by presenting a deceptive interface.

Technical details

A UI spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the browser's interface handling. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to spoof UI elements, potentially facilitating phishing or other social engineering attacks. The vulnerability is addressed in version 150.0.7871.47. The Chromium project assigned this a Medium severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD publication date
  • 2026-06-30: patched: Chrome 150.0.7871.47 released

References

Related threats