Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to spoof the browser's user interface. This means an attacker could trick a user into thinking they are on a legitimate site or interacting with a trusted browser element when they are not. Such attacks are typically used to facilitate phishing or to deceive users into performing unintended actions.
Technical details
A UI spoofing vulnerability exists in Google Chrome for iOS due to an inappropriate implementation within the browser's interface handling. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent or overlap parts of the browser's user interface, potentially leading to phishing or user confusion. The vulnerability is rated as Low severity by Chromium and is addressed in version 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed