Description
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the Omnibox component of Google Chrome for iOS versions earlier than 150.0.7871.47 allows a remote attacker to inject arbitrary scripts or HTML through a crafted page after a user performs a specific UI gesture. The vulnerability is categorized as a User Interaction–Triggered Script Injection (UXSS) and is associated with CWE-79.

Affected Systems

Google Chrome for iOS older than version 150.0.7871.47 is affected. The flaw is removed in the 150.0.7871.47 release and later.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity, and the EPSS score of less than 1 % reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale incidents have been reported. Exploitation requires a user to be persuaded to perform the specific UI gesture after visiting a malicious page, indicating that the attack vector is user‑interaction dependent.

Generated by OpenCVE AI on August 3, 2026 at 06:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome for iOS to version 150.0.7871.47 or newer.
  • Enable automatic updates on the device so Chrome receives future security patches.
  • Educate users to avoid performing unusual UI gestures after visiting untrusted webpages and to confirm the URL before interacting.

Generated by OpenCVE AI on August 3, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title User Interaction–Triggered Script Injection in Chrome iOS Omnibox

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title User Interaction–Triggered Script Injection in Chrome iOS Omnibox

Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title UI Gesture-Based Cross‑Site Script Injection in Chrome iOS Omnibox

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title UI Gesture-Based Cross‑Site Script Injection in Chrome iOS Omnibox

Sun, 12 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Cross-Site Scripting via Chrome iOS Omnibox

Fri, 10 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Cross-Site Scripting via Chrome iOS Omnibox

Thu, 09 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS Enables Arbitr Interaction on iOS Chrome

Wed, 08 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS Enables Arbitr Interaction on iOS Chrome

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Inappropriate Omnibox Implementation Allowing User-Engagement XSS in Chrome iOS

Mon, 06 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Inappropriate Omnibox Implementation Allowing User-Engagement XSS in Chrome iOS

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS UXSS via UI Gesture Abuse

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome iOS UXSS via UI Gesture Abuse

Sat, 04 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title User‑Engagement Based Script Injection in Chrome on iOS

Fri, 03 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title User‑Engagement Based Script Injection in Chrome on iOS

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS in Chrome for iOS via Crafted HTML Page

Fri, 03 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Omnibox UXSS in Chrome for iOS via Crafted HTML Page

Thu, 02 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Chrome iOS Omnibox Enables Remote Script Injection via User Interaction

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title UXSS Vulnerability in Chrome iOS Omnibox Enables Remote Script Injection via User Interaction

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title UXSS via Arbitrary Script Injection in Chrome on iOS
Weaknesses CWE-94

Wed, 01 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title UXSS via Arbitrary Script Injection in Chrome on iOS
Weaknesses CWE-94

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title User-Engagement UXSS Vulnerability in Chrome iOS Omnibox
Weaknesses CWE-79

Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title User-Engagement UXSS Vulnerability in Chrome iOS Omnibox
Weaknesses CWE-79

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T12:56:03.290Z

Reserved: 2026-06-29T23:11:35.657Z

Link: CVE-2026-14068

cve-icon Vulnrichment

Updated: 2026-07-01T12:55:54.299Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')