Description
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome for iOS implements rendering incorrectly, which allows a remote attacker to perform UI spoofing through a crafted HTML page. The flaw permits the browser to overlay or render user interface elements that mimic the browser’s native controls, potentially disguising malicious content. This weakness is categorized as information exposure (CWE‑451). Based on the description, it is inferred that an attacker can trigger the flaw by delivering a crafted HTML page to a victim’s browser.

Affected Systems

Any Google Chrome for iOS build older than version 150.0.7871.47 is affected. This includes all iOS devices running Chrome before that update, regardless of brand or carrier.

Risk and Exploitability

The CVSS score of 4.3 indicates medium severity, and the EPSS score of less than 1% reflects an extremely low likelihood of exploitation. The vulnerability is not in CISA’s KEV catalog. Exploitation requires only that a victim open a crafted HTML page in Chrome; no local privileges or additional setup are needed. The impact is limited to user deception and potential phishing, which does not compromise confidentiality or integrity of the device or data beyond possible user credential fields. The likely attack vector is inferred to be remote access via a crafted HTML page opened in Chrome.

Generated by OpenCVE AI on July 21, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome for iOS to version 150.0.7871.47 or newer, which removes the rendering flaw that allows UI spoofing.
  • If an immediate update is not possible, consider temporarily disabling JavaScript in Chrome for untrusted sites to reduce the risk of UI spoofing for web pages that may contain malicious UI layering.
  • Educate users to be cautious when entering credentials on sites loaded in Chrome, especially on older builds, and to verify URLs before inputting sensitive information.

Generated by OpenCVE AI on July 21, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Improper Rendering in Chrome for iOS

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Improper Rendering in Chrome for iOS

Sun, 12 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS via Crafted HTML

Sun, 12 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS via Crafted HTML

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome for iOS

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome for iOS

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome for iOS

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome for iOS

Mon, 06 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS Enables Remote Attacker to Mimic Browser Interface

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS Enables Remote Attacker to Mimic Browser Interface

Thu, 02 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page
Weaknesses CWE-1125

Thu, 02 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page
Weaknesses CWE-1125
CWE-79

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome for iOS
Weaknesses CWE-79

Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome for iOS
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T00:41:46.385Z

Reserved: 2026-06-29T23:04:07.400Z

Link: CVE-2026-13980

cve-icon Vulnrichment

Updated: 2026-07-01T19:26:17.947Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T16:30:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information