Executive brief
A security issue in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's URL bar. This type of flaw is typically used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent page. Users are advised to update their Chrome app to the latest version to ensure the address bar correctly reflects the site they are visiting.
Technical details
A UI spoofing vulnerability exists in Google Chrome for iOS due to an incorrect security UI implementation in the Omnibox (address bar). By enticing a user to visit a specially crafted HTML page, a remote attacker can manipulate the displayed URL, potentially leading to successful phishing or social engineering attacks. The vulnerability stems from how the browser handles UI updates during specific page transitions or rendering states. This issue is resolved in version 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed