Junglewise Threat Intelligence

CVE-2026-13907: Google Chrome UI spoofing in iOSWeb

CVE-2026-13907 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to trick users into performing unintended actions. By convincing a user to perform specific touch gestures on a specially crafted webpage, an attacker can spoof parts of the browser's user interface. This could be used to deceive users into thinking they are interacting with a legitimate site or browser feature, potentially leading to further social engineering attacks.

Technical details

An inappropriate implementation in the iOSWeb component of Google Chrome for iOS allowed for UI spoofing. A remote attacker could exploit this by hosting a crafted HTML page and convincing a user to engage in specific UI gestures. This interaction allows the attacker to manipulate or misrepresent the browser's user interface elements. The vulnerability is fixed in version 150.0.7871.47. The issue is categorized by Chromium as Medium severity.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats