Junglewise Threat Intelligence

CVE-2026-13983: Google Chrome for iOS Omnibox spoofing via UI gestures

CVE-2026-13983 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A security issue in Google Chrome for iOS could allow a malicious website to trick users by showing a fake web address in the browser's address bar. By convincing a user to perform specific touch gestures on a specially crafted page, an attacker could make their site appear to be a legitimate or trusted website. This type of flaw is typically used in phishing attacks to steal login credentials or sensitive information by deceiving the user about which site they are actually visiting.

Technical details

A URL spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the UI handling logic. A remote attacker can exploit this by hosting a specially crafted HTML page and convincing a user to perform specific UI gestures. Successful exploitation allows the attacker to manipulate the contents of the Omnibox (address bar), potentially leading to effective phishing or social engineering attacks. The vulnerability is addressed in version 150.0.7871.47.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats