Executive brief
A security issue in Google Chrome for iOS could allow a malicious website to display deceptive information within the browser's password management interface. This could be used to trick users into performing unintended actions or believing they are interacting with a legitimate security prompt. Users should update to the latest version of Chrome to resolve this issue.
Technical details
A UI spoofing vulnerability exists in the Password management component of Google Chrome for iOS. The flaw stems from an incorrect security UI implementation that fails to properly isolate or validate interface elements when rendering certain content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to misrepresent security information or spoof the password manager's interface. This issue is fixed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched