Junglewise Threat Intelligence

CVE-2026-17822: Google Chrome for iOS race condition UI spoofing

CVE-2026-17822 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome for iOS that could allow a malicious website to spoof the browser's user interface. By tricking a user into visiting a specially crafted webpage, an attacker could display misleading information or fake browser elements to facilitate phishing or other deceptive attacks. This issue affects users on Apple mobile devices running versions of Chrome older than 151.0.7922.72.

Technical details

A race condition vulnerability was identified in the Chrome for iOS component of Google Chrome. The flaw exists in versions prior to 151.0.7922.72 and can be triggered by a remote attacker who convinces a user to load a maliciously crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misrepresenting the origin or state of the browser to the user. The vulnerability is categorized by Chromium as Medium severity and has been addressed in the stable channel update for iOS.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats