Junglewise Threat Intelligence

CVE-2026-17849: Google Chrome for iOS URL spoofing in Omnibox

CVE-2026-17849 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's address bar. This could be used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent one. Users should update to the latest version of Chrome on their iOS devices to resolve this issue.

Technical details

An inappropriate implementation in the Omnibox (URL bar) component of Google Chrome for iOS allowed a remote attacker to spoof the displayed URL. By delivering malicious network traffic or leveraging specific page transitions, an attacker could cause the browser to display a legitimate domain name while the user is actually viewing attacker-controlled content. This is a UI spoofing vulnerability that bypasses the user's ability to verify the authenticity of a website. The issue is resolved in version 151.0.7922.72.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats