Junglewise Threat Intelligence

CVE-2026-18016: Google Chrome for iOS UI spoofing via insufficient policy enforcement

CVE-2026-18016 · Severity: info · CVSS 0 · Published 2026-07-30

Executive brief

Google Chrome for iOS is a mobile web browser. A vulnerability in versions prior to 151.0.7922.72 allowed a remote attacker to trick users by spoofing parts of the browser's user interface. This could be used to facilitate phishing attacks or mislead users about the security status of a website.

Technical details

A UI spoofing vulnerability exists in Google Chrome for iOS due to insufficient policy enforcement. By convincing a user to visit a specially crafted HTML page, a remote attacker could manipulate or spoof elements of the browser's user interface. This issue is categorized by Chromium as 'Low' severity. The vulnerability is addressed in version 151.0.7922.72. No authentication or special privileges are required beyond the ability to serve a malicious webpage to the victim.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats