Executive brief
A security vulnerability in Google Chrome for iOS could allow a malicious website to trick users into performing unintended actions. By convincing a user to perform specific touch gestures on a specially crafted webpage, an attacker can spoof parts of the browser's user interface. This could lead to phishing attacks where the user is misled about the security or origin of the site they are visiting.
Technical details
An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw allows a remote attacker to perform UI spoofing by leveraging insufficient validation of untrusted input during user interactions. To exploit the vulnerability, an attacker must entice a user to visit a malicious HTML page and engage in specific UI gestures. Successful exploitation allows the attacker to misrepresent the browser's user interface, potentially facilitating phishing or other social engineering attacks. Google has addressed this issue in version 150.0.7871.47.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched