Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate website or interacting with a trusted browser feature, potentially leading to credential theft or other social engineering attacks. Users should update to the latest version of Chrome on their iOS devices to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the browser's interface handling. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to manipulate or spoof elements of the browser's user interface, which can be leveraged for phishing or social engineering. The vulnerability is addressed in version 150.0.7871.47.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched