Junglewise Threat Intelligence

CVE-2026-14136: Google Chrome UI spoofing in Chrome for iOS

CVE-2026-14136 · Severity: info · Published 2026-06-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS, a popular mobile web browser, was found to have a security flaw that could allow a malicious website to spoof parts of the browser's user interface. An attacker could use this to trick users into believing they are on a legitimate site or interacting with a trusted browser element, potentially leading to phishing or unauthorized actions. Users should update to the latest version of Chrome on their iOS devices to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw stems from insufficient validation of untrusted input when processing specially crafted HTML pages. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, allowing the attacker to misrepresent the browser's user interface. This is categorized by Chromium as a Low severity issue. The vulnerability is addressed in version 150.0.7871.47.

Affected products

  • Google Chrome for iOS prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats