Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate website or interacting with a trusted browser feature, potentially leading to phishing or the disclosure of sensitive information. Users should update their Chrome application on iOS to the latest version to mitigate this risk.
Technical details
A UI spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation within the browser's interface handling. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to manipulate or misrepresent the browser's user interface elements, which can facilitate phishing attacks. The issue is fixed in version 151.0.7922.72. Chromium developers have classified this as a Low severity security issue.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date