Description
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that a remote attacker can manipulate the contents shown in the Chrome for iOS address bar by sending specially crafted network traffic. This allows the attacker to display misleading or falsified URLs to a user, potentially leading to phishing or other deceptive attacks. The main consequence is the compromise of user trust and the potential for accidental navigation to malicious sites.

Affected Systems

Chrome for iOS versions earlier than 151.0.7922.72 are affected. All iOS devices running these versions of Chrome can be impacted by this flaw.

Risk and Exploitability

The problem is rated as a medium‑severity issue by Chromium security, but its EPSS score is less than 1%, indicating a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need to deliver the malicious traffic over the network without any local interactions, implying the attack can be performed remotely from a position that can influence network traffic to the victim’s device.

Generated by OpenCVE AI on August 3, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome for iOS version 151.0.7922.72 or newer to receive the official fix.
  • Limit exposure to untrusted Wi‑Fi networks or use a VPN that filters malicious traffic.
  • Keep the browser updated automatically to ensure timely application of security patches.

Generated by OpenCVE AI on August 3, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Mon, 03 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Omnibox Spoofing via Network Traffic in Chrome for iOS

Fri, 31 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T18:19:25.977Z

Reserved: 2026-07-27T23:35:03.968Z

Link: CVE-2026-17849

cve-icon Vulnrichment

Updated: 2026-07-31T18:19:20.262Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:48.567

Modified: 2026-07-31T21:21:16.803

Link: CVE-2026-17849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:00:16Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information