Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to misrepresent its identity or display deceptive content to users. By tricking the browser's user interface, an attacker could potentially facilitate phishing attacks or mislead users into performing unintended actions. Users are advised to update their mobile browser to the latest version to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the browser's interface handling. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to manipulate or spoof elements of the browser's user interface, which can be leveraged for phishing or other social engineering attacks. The issue is addressed in version 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date