Junglewise Threat Intelligence

CVE-2026-17965: Google Chrome for iOS UI spoofing via crafted HTML page

CVE-2026-17965 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

Google Chrome for iOS is a popular mobile web browser. A vulnerability in the application's user interface could allow a malicious website to misrepresent security information or spoof parts of the browser's interface. This could be used to trick users into believing they are on a legitimate site when they are actually on a malicious one, potentially leading to credential theft or other phishing-related activities.

Technical details

A UI spoofing vulnerability exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw is categorized as an 'Incorrect security UI' implementation, which allows a remote attacker to manipulate the browser's interface elements. By enticing a user to visit a specially crafted HTML page, an attacker can spoof security indicators or other UI components. This is rated as Low severity by Chromium. The issue is addressed in the stable channel update 151.0.7922.72.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats