Junglewise Threat Intelligence

CVE-2026-13980: Google Chrome UI spoofing in Chrome for iOS

CVE-2026-13980 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are on a legitimate site when they are not. Users should update to the latest version of Chrome on their iOS devices to mitigate this risk.

Technical details

An inappropriate implementation in the iOS version of Google Chrome allowed for UI spoofing. By enticing a user to visit a specially crafted HTML page, a remote attacker could manipulate or misrepresent elements of the browser's user interface. This vulnerability is categorized by Chromium as Medium severity. The issue is resolved in version 150.0.7871.47 and later. Exploitation requires user interaction (visiting a malicious site).

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats