Executive brief
A security interface issue in Google Chrome for iOS could allow a malicious website to trick users. By convincing a user to perform specific touch gestures, an attacker could display misleading information or fake interface elements. This could lead to users being deceived into providing sensitive information to a fraudulent site that appears legitimate.
Technical details
A UI spoofing vulnerability exists in Google Chrome for iOS prior to version 150.0.7871.47 due to an incorrect security UI implementation. A remote attacker can exploit this by hosting a crafted HTML page and tricking a user into performing specific UI gestures. Successful exploitation allows the attacker to misrepresent the browser's security state or spoof interface elements. This issue is categorized by Chromium as Low severity and has been addressed in the 150.0.7871.47 update.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched