Junglewise Threat Intelligence

CVE-2026-17841: Google Chrome for iOS race condition UI spoofing

CVE-2026-17841 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome for iOS that could allow a malicious website to spoof the browser's user interface. By tricking a user into visiting a specially crafted webpage, an attacker could potentially display fake information or mimic legitimate browser elements to deceive the user. This could lead to phishing attacks where users are misled into providing sensitive information to a fraudulent site.

Technical details

A race condition (CWE-362) exists in the Chrome for iOS component of Google Chrome. The vulnerability is triggered when a remote attacker serves a specially crafted HTML page that exploits improper synchronization during concurrent execution. Successful exploitation allows the attacker to perform UI spoofing, potentially bypassing visual security indicators or misrepresenting the origin of content. The issue is resolved in Google Chrome for iOS version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats