Junglewise Threat Intelligence

CVE-2026-17972: Google Chrome for iOS UI spoofing via crafted HTML page

CVE-2026-17972 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome for iOS, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate website or interacting with a trusted browser prompt, potentially leading to phishing or unauthorized actions. Users should update to the latest version of Chrome on their iOS devices to mitigate this risk.

Technical details

An inappropriate implementation in Google Chrome for iOS prior to version 151.0.7922.72 allowed a remote attacker to perform UI spoofing. The vulnerability is triggered when a user visits a specially crafted HTML page controlled by the attacker. By manipulating the browser's interface elements, the attacker can misrepresent the origin or state of the web page. This issue is categorized by Chromium as Low severity. A fix is available in version 151.0.7922.72 and later.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: patched
  • 2026-07-30: advisory

References

Related threats