Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's address bar. This could be used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent one. Users are advised to update their browser to the latest version to prevent potential credential or data theft.
Technical details
A User Interface (UI) Misrepresentation vulnerability (CWE-451) exists in the Omnibox (address bar) component of Google Chrome for iOS. The flaw stems from incorrect handling of specially crafted domain names, which allows a remote attacker to spoof the URL displayed to the user. Exploitation requires a user to visit a malicious link. If successful, an attacker can perform address bar spoofing to facilitate phishing or other social engineering attacks. The issue is resolved in version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2024-10-18: other: Reported by Renwa Hiwa
- 2026-04-07: patched: Stable channel update released
- 2026-04-08: disclosed: Public advisory published