Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate website or interacting with a trusted browser feature, potentially leading to the theft of sensitive information or credentials. Users are advised to update their Chrome application to the latest version to mitigate this risk.
Technical details
An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw allows a remote attacker to perform UI spoofing by enticing a user to visit a maliciously crafted HTML page. This class of vulnerability typically involves the browser failing to correctly isolate or validate elements of the user interface when rendering web content, allowing the attacker to overlay or mimic trusted UI components. Google has addressed this issue in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date