Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's address bar. This could be used in phishing attacks to trick users into believing they are visiting a legitimate site when they are actually on a fraudulent one. Users are advised to update their Chrome app to the latest version to resolve this issue.
Technical details
A URL spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the Omnibox component. By enticing a user to visit a specially crafted HTML page, a remote attacker can manipulate the address bar to display a fraudulent URL while the browser remains on the attacker-controlled site. This flaw is categorized by Chromium as Low severity and is addressed in version 150.0.7871.47. The attack requires no special privileges but does require the victim to navigate to a malicious webpage.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched