Description
Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in Google Chrome for iOS before version 151.0.7922.72 can allow a remote attacker to craft an HTML page that triggers UI spoofing. The attacker can cause visible UI elements to appear misleading, potentially tricking users into interacting with malicious content. Although the bug does not grant code execution, the resulting deceptive interface can be used for phishing or other fraud vehicles. Based on the description, the attack vector appears to be a web‑based exploit rather than a local code execution pathway.

Affected Systems

The affected product is Google Chrome for iOS. Devices running Chrome on iOS with a build number older than 151.0.7922.72 are vulnerable. No other vendors or product variants are listed.

Risk and Exploitability

The EPSS score is below 1 %, indicating a low probability of exploitation, but the Chromium severity is marked as Medium. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Without a public exploit, the risk remains moderate, yet the potential for malicious UI redirection could still impact user confidentiality and luring them into fraudulent actions if attackers gain an audience. Attackers would need to serve a crafted HTML page to the target device, making the vector remote via the web.

Generated by OpenCVE AI on August 2, 2026 at 06:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome on the affected iOS device to version 151.0.7922.72 or later. This closes the race condition that enabled the UI spoofing.
  • Enable Chrome’s Safe Browsing and Insecure Content Filtering to detect and block malicious UI tactics on the device.
  • Educate users on recognizing legitimate UI cues and encourage them to be wary of unexpected prompts or changes in page layouts, especially when entering sensitive information.

Generated by OpenCVE AI on August 2, 2026 at 06:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sun, 02 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Race Condition Enables Remote UI Spoofing

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T15:30:48.003Z

Reserved: 2026-07-27T23:34:57.648Z

Link: CVE-2026-17822

cve-icon Vulnrichment

Updated: 2026-07-31T15:30:42.803Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:45.767

Modified: 2026-08-03T17:41:14.037

Link: CVE-2026-17822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:45:03Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')