Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate site or interacting with a trusted browser security warning when they are not. This type of attack is typically used in phishing campaigns to steal credentials or sensitive information.
Technical details
A UI spoofing vulnerability exists in the Safe Browsing component of Google Chrome for iOS. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements when processing specifically crafted HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage, allowing the attacker to misrepresent browser security states or interface elements. This issue was addressed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched