Junglewise Threat Intelligence

CVE-2026-8584: Google Chrome for iOS UI spoofing in Views

CVE-2026-8584 · Severity: medium · CVSS 4.2 · Published 2026-05-14

Technologies: Apple Iphone Os, Google Chrome. Vendors: Apple, Google.

Executive brief

A vulnerability in Google Chrome for iOS could allow a malicious website to misrepresent or spoof parts of the browser's user interface. This occurs if an attacker has already partially compromised the browser's internal processing components, allowing them to trick users into performing unintended actions or trusting a fake interface. Users are protected by updating to the latest version of the Chrome app.

Technical details

A UI spoofing vulnerability exists in the 'Views' component of Google Chrome for iOS. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements when handled by the renderer process. An attacker who has already achieved code execution within a compromised renderer process can exploit this to manipulate the browser's user interface via a specially crafted HTML page. This could be used to facilitate phishing or other social engineering attacks by displaying deceptive browser chrome or dialogs. The issue is resolved in version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Stable channel update released for desktop and iOS versions.
  • 2026-05-14: disclosed: CVE published to NVD.

References

Related threats