Junglewise Threat Intelligence

CVE-2026-17839: Google Chrome for iOS UI spoofing via crafted HTML page

CVE-2026-17839 · Severity: info · Published 2026-07-30

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate website or to hide security warnings, potentially leading to credential theft or other phishing attacks. Users should update their Chrome app on iOS to the latest version to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform user interface (UI) spoofing, which can be leveraged to misrepresent website identity or browser state. The vulnerability is categorized by Chromium as Medium severity. A fix is available in version 151.0.7922.72 and later.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released
  • 2026-07-30: disclosed: NVD publication date

References

Related threats