Executive brief
A vulnerability in Google Chrome for macOS could allow a malicious website to display a fake web address in the browser's URL bar. This type of flaw is typically used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent page. Users are advised to update their browser to the latest version to prevent this spoofing.
Technical details
An inappropriate implementation in the 'Select' component of Google Chrome on macOS allowed a remote attacker to spoof the contents of the Omnibox (URL bar). By enticing a user to visit a specially crafted HTML page, an attacker could manipulate the displayed URL to facilitate phishing or social engineering attacks. The vulnerability is specific to the Mac platform and was addressed in version 150.0.7871.47. Chromium developers classified this as a Low severity issue.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched