Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate website or to hide security warnings, potentially leading to credential theft or other phishing attacks. Users should update their Chrome app on iOS to the latest version to mitigate this risk.
Technical details
An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform user interface (UI) spoofing, which can be leveraged to misrepresent website identity or browser state. The vulnerability is categorized by Chromium as Medium severity. A fix is available in version 151.0.7922.72 and later.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released
- 2026-07-30: disclosed: NVD publication date