Description
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in Chrome for iOS allows a remote attacker to perform UI spoofing via a crafted HTML page. The flaw, classified as CWE-451, enables an attacker to overlay or manipulate the browser’s visual interface, potentially misleading users about the authenticity of displayed content. The CVE data does not indicate code execution; the impact is limited to UI manipulation.

Affected Systems

Affected systems include all iOS devices running Google Chrome versions earlier than 150.0.7871.47. The vulnerability is present in the iOS build of Chrome and affects all installations without the patch.

Risk and Exploitability

The CVSS score of 4.3 indicates medium impact, while the EPSS score of less than 1 % points to a low probability of exploitation. The vulnerability is not included in CISA's KEV catalog. The likely attack vector is a web‑based exploit where an attacker hosts a malicious page and lures a user into opening it under an unpatched Chrome for iOS. In such a scenario, the attacker can manipulate the UI to deceive the user.

Generated by OpenCVE AI on July 16, 2026 at 12:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome for iOS to version 150.0.7871.47 or newer.
  • Ensure automatic updates are enabled or enforce an organization‑wide update policy to apply fixes promptly.
  • Educate users about UI spoofing attacks and consider deploying device or network controls to detect or block suspicious domains.

Generated by OpenCVE AI on July 16, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Google Chrome for iOS Enabling Remote Manipulation of Browser Interface

Tue, 14 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title iOS Chrome UI Spoofing via Crafted HTML Page

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title iOS Chrome UI Spoofing via Crafted HTML Page

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome for iOS

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome for iOS

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome iOS UI Spoofing via Crafted HTML Page

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS UI Spoofing via Crafted HTML Page

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page

Sat, 04 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Fri, 03 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page
Weaknesses CWE-1335

Thu, 02 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page
Weaknesses CWE-1335

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Google Chrome for iOS
Weaknesses CWE-79

Wed, 01 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Google Chrome for iOS
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:26:19.865Z

Reserved: 2026-06-29T23:03:51.359Z

Link: CVE-2026-13916

cve-icon Vulnrichment

Updated: 2026-07-01T14:26:12.353Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:30:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information