Executive brief
Google Chrome for iOS is a mobile web browser. A security flaw in how the browser displays website information could allow a malicious website to appear as if it belongs to a different, trusted domain. This could be used in phishing attacks to trick users into entering sensitive information on a fraudulent site that looks legitimate.
Technical details
A domain spoofing vulnerability exists in Google Chrome for iOS due to an incorrect security UI implementation. By utilizing a specially crafted HTML page, a remote attacker can manipulate the browser's user interface to display an incorrect domain name. This flaw allows for the bypass of visual security indicators that users rely on to verify the authenticity of a website. The vulnerability is present in versions prior to 151.0.7922.72 and requires user interaction (visiting a malicious link) to exploit. Google has addressed this issue in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date