Description
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome for iOS contains a flaw in the Omnibox that permits a remote attacker to inject arbitrary scripts or HTML into a page viewed by the victim. The injection is achieved when the victim performs a specific UI gesture following by a malicious page. The code runs in the context of the page, enabling malicious actions. This vulnerability is a form of cross‑site scripting (CWE‑79).

Affected Systems

Chrome browsers on iOS running versions earlier than 150.0.7871.47 are vulnerable. The fix is included in Chrome iOS 150.0.7871.47 and later. Users on older releases, or those who have not updated, remain at risk.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1 % points to a low probability of exploitation. CISA’s KEV catalog, suggesting no large‑scale attacks have been observed. Based on the description, it is inferred that the attacker must convince a user to execute a specific gesture in Chrome’s interface, after which the injected script runs. Thus exploitation requires social engineering and is unlikely to be a widespread automated attack.

Generated by OpenCVE AI on July 17, 2026 at 13:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome for iOS to version 150.0.7871.47 or later.
  • Enable automatic updates on iOS or instruct users to manually upgrade Chrome to the latest release.
  • Educate users to avoid performing unexpected UI gestures after interacting with untrusted webpages and to verify the origin of URLs before clicking.

Generated by OpenCVE AI on July 17, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title UI Gesture-Based Cross‑Site Script Injection in Chrome iOS Omnibox

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title UI Gesture-Based Cross‑Site Script Injection in Chrome iOS Omnibox

Sun, 12 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Cross-Site Scripting via Chrome iOS Omnibox

Fri, 10 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Cross-Site Scripting via Chrome iOS Omnibox

Thu, 09 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS Enables Arbitr Interaction on iOS Chrome

Wed, 08 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS Enables Arbitr Interaction on iOS Chrome

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Inappropriate Omnibox Implementation Allowing User-Engagement XSS in Chrome iOS

Mon, 06 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Inappropriate Omnibox Implementation Allowing User-Engagement XSS in Chrome iOS

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS UXSS via UI Gesture Abuse

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome iOS UXSS via UI Gesture Abuse

Sat, 04 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title User‑Engagement Based Script Injection in Chrome on iOS

Fri, 03 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title User‑Engagement Based Script Injection in Chrome on iOS

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS in Chrome for iOS via Crafted HTML Page

Fri, 03 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS in Chrome for iOS via Crafted HTML Page

Thu, 02 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Chrome iOS Omnibox Enables Remote Script Injection via User Interaction

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Chrome iOS Omnibox Enables Remote Script Injection via User Interaction

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title UXSS via Arbitrary Script Injection in Chrome on iOS
Weaknesses CWE-94

Wed, 01 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title UXSS via Arbitrary Script Injection in Chrome on iOS
Weaknesses CWE-94

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title User-Engagement UXSS Vulnerability in Chrome iOS Omnibox
Weaknesses CWE-79

Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title User-Engagement UXSS Vulnerability in Chrome iOS Omnibox
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T12:56:03.290Z

Reserved: 2026-06-29T23:11:35.657Z

Link: CVE-2026-14068

cve-icon Vulnrichment

Updated: 2026-07-01T12:55:54.299Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')