Junglewise Threat Intelligence

CVE-2026-18003: Google Chrome for iOS UI spoofing via crafted HTML page

CVE-2026-18003 · Severity: info · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into believing they are on a legitimate site or interacting with a trusted browser element, potentially leading to phishing or the disclosure of sensitive information. Users should update to the latest version of Chrome on their iOS devices to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation within the browser's interface handling. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent or overlap browser UI elements, which can be leveraged for phishing attacks. The issue is addressed in version 151.0.7922.72. Chromium has assigned this a security severity of Low.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: patched
  • 2026-07-30: advisory

References

Related threats