Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to misrepresent its identity or display deceptive content to users. By tricking the browser's user interface, an attacker could potentially facilitate phishing attacks or mislead users into performing unintended actions. This issue affects users on iPhones and iPads who have not updated to the latest version of the browser.
Technical details
An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw allows a remote attacker to perform UI spoofing via a crafted HTML page. By exploiting this weakness, an attacker can manipulate or misrepresent parts of the browser's user interface, which is often a precursor to phishing or social engineering attacks. The attack requires the victim to navigate to a malicious website (User Interaction required). Google has addressed this issue in the stable channel update 150.0.7871.47.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched