Executive brief
A security issue in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's address bar (Omnibox). This type of flaw is typically used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent page. Users are advised to update their browser to the latest version to prevent this visual deception.
Technical details
A URL spoofing vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72 due to an inappropriate implementation in the Omnibox component. By convincing a user to visit a specially crafted HTML page, a remote attacker can manipulate the address bar to display a fraudulent URL while the browser remains on the attacker-controlled site. This is a client-side attack vector that bypasses visual security indicators intended to verify the site's identity. The issue is resolved in version 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed