Junglewise Threat Intelligence

CVE-2026-5898: Google Chrome for iOS UI spoofing in Omnibox

CVE-2026-5898 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to misrepresent its identity in the browser's address bar (Omnibox). By tricking the browser into displaying an incorrect security UI, an attacker could perform a phishing attack to steal user credentials or sensitive information. Users are protected by updating to the latest version of the Chrome app.

Technical details

A UI spoofing vulnerability exists in the Omnibox (address bar) component of Google Chrome for iOS prior to version 147.0.7727.55. The flaw stems from an incorrect security UI implementation that can be manipulated by a remote attacker using a specially crafted HTML page. By exploiting this, an attacker can misrepresent critical security information or the origin of a website to a user. This requires user interaction, specifically visiting a malicious site. The issue is addressed in version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2025-12-19: other: Reported to Chromium project
  • 2026-04-07: patched: Fixed in stable channel release 147.0.7727.55
  • 2026-04-08: disclosed: Public advisory published

References

Related threats