Junglewise Threat Intelligence

CVE-2026-14123: Google Chrome for iOS URL spoofing in Omnibox

CVE-2026-14123 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A security interface flaw in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's address bar. This could be used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or login portal, when they are actually on a fraudulent page. Users are advised to update to the latest version of Chrome on their iOS devices to resolve this issue.

Technical details

A vulnerability in the security UI of Google Chrome for iOS allowed a remote attacker to perform Omnibox (URL bar) spoofing. The flaw stems from an inappropriate implementation of the user interface when handling specific HTML content, which fails to correctly display the true origin of a page. An attacker can exploit this by enticing a user to visit a malicious website, which then uses crafted HTML to overwrite or mask the address bar contents. This issue was addressed in Google Chrome for iOS version 150.0.7871.47. No user interaction beyond visiting the site is required for the spoofing to occur.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats