Junglewise Threat Intelligence

CVE-2026-13916: Google Chrome UI spoofing in Chrome for iOS

CVE-2026-13916 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate website or interacting with a trusted browser feature, potentially leading to credential theft or other phishing attacks. Users should update to the latest version of Chrome on their iOS devices to mitigate this risk.

Technical details

An inappropriate implementation in Google Chrome for iOS prior to version 150.0.7871.47 allows a remote attacker to perform user interface (UI) spoofing. By convincing a user to visit a specially crafted HTML page, an attacker can manipulate or misrepresent browser UI elements. This vulnerability is categorized by Chromium as Medium severity. The issue is addressed in version 150.0.7871.47 and later. No authentication or special privileges are required beyond the user navigating to the malicious content.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats