Junglewise Threat Intelligence

CVE-2026-5895: Google Chrome for iOS address bar spoofing in Omnibox

CVE-2026-5895 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to display a fake web address in the browser's address bar. This could be used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent one. Users are advised to update their browser to the latest version to prevent potential credential or data theft.

Technical details

A User Interface (UI) Misrepresentation vulnerability (CWE-451) exists in the Omnibox (address bar) component of Google Chrome for iOS. The flaw stems from incorrect handling of specially crafted domain names, which allows a remote attacker to spoof the URL displayed to the user. Exploitation requires a user to visit a malicious link. If successful, an attacker can perform address bar spoofing to facilitate phishing or other social engineering attacks. The issue is resolved in version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2024-10-18: other: Reported by Renwa Hiwa
  • 2026-04-07: patched: Stable channel update released
  • 2026-04-08: disclosed: Public advisory published

References

Related threats