Description
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome for iOS versions earlier than 150.0.7871.47 contain interface elements that appear legitimate to users. This flaw is identified as CWE‑451, meaning a crafted HTML page can simulate user interfaces such that a user may be deceived into interacting with a false dialog box or form. The attacker can thus trick a user into entering sensitive information. The vulnerability does not enable arbitrary code execution or device compromise; it is limited to UI deception, consistent with the CVSS score of 4.3.

Affected Systems

All builds of Google Chrome for iOS prior to version 150.0.7871.47 are affected. Later releases contain the correction and are therefore not vulnerable.

Risk and Exploitability

The vulnerability can be exploited through a remote crafted HTML page, giving an attacker the ability to perform UI spoofing. The moderate CVSS score indicates a non‑critical risk, while the EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild. Because the vulnerability is not listed in the CISA KEV catalog, no widespread exploits are documented. The attack vector is remote, governed by the web interface, and the impact is limited to user deception rather than system compromise.

Generated by OpenCVE AI on August 3, 2026 at 06:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome for iOS to version 150.0.7871.47 or later to apply the UI spoofing fix.
  • Enable Chrome’s phishing detection and other UI‑security protections to reduce the risk of deceptive pages.
  • Exercise caution when encountering unfamiliar web pages: verify a site’s origin before submitting sensitive information, as a preventive measure against UI spoofing attacks.

Generated by OpenCVE AI on August 3, 2026 at 06:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome iOS UI Spoofing via Crafted HTML

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS UI Spoofing via Crafted HTML

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS via Crafted Web Page

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS via Crafted Web Page

Sun, 12 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Google Chrome for iOS Prior to Version 150.0.7871.47

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Google Chrome for iOS Prior to Version 150.0.7871.47

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome for iOS

Tue, 07 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome for iOS

Mon, 06 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing Vulnerability

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Webpage in Chrome for iOS

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Webpage in Chrome for iOS

Thu, 02 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page

Thu, 02 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page
Weaknesses CWE-1031

Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS UI Spoofing via Crafted HTML Page
Weaknesses CWE-1031

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:23:58.467Z

Reserved: 2026-06-29T23:04:07.664Z

Link: CVE-2026-13981

cve-icon Vulnrichment

Updated: 2026-07-01T19:23:53.982Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:45:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information