Junglewise Threat Intelligence

CVE-2026-17874: Google Chrome for iOS UI spoofing via crafted HTML page

CVE-2026-17874 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to misrepresent its identity or display deceptive content. By tricking the browser's user interface, an attacker could potentially lure users into providing sensitive information to a fraudulent site that appears legitimate. Users are advised to update their mobile browser to the latest version to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation within the browser's interface handling. A remote attacker can exploit this by inducing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to manipulate or spoof elements of the browser's user interface, potentially leading to phishing or other social engineering attacks. The issue is addressed in version 151.0.7922.72.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats