Description
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates from an inappropriate implementation in Chrome for iOS that enables UI spoofing when a malicious webpage is rendered. Attackers can create a crafted HTML page that tricks users into interacting with deceptive interface elements. This flaw poses a phishing risk but does not allow execution of code or privileged operations. Based on the description, the attack vector is a malicious Web page loaded in the browser. The weakness aligns with CWE-451.

Affected Systems

Google Chrome on iOS versions prior to 151.0.7922.72. Users running any older mobile Chrome build are vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is below 1% and the flaw is not in the KEV catalog, indicating a low likelihood of active exploitation at this time. Security teams should note the limited attack surface: a threat actor must host a malicious web page that a user visits and interacts with. While rare, the impact includes credential theft or misleading user actions. Upgrading to the fixed version provides the only documented solution.

Generated by OpenCVE AI on August 5, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome on iOS to version 151.0.7922.72 or newer, which contains the correction for the UI spoofing flaw.
  • Limit exposure by avoiding untrusted or unknown web pages in Chrome on iOS until the update is applied.
  • Configure device security settings or browser content policies to reduce interaction with potential phishing sites, such as enabling safe browsing features.

Generated by OpenCVE AI on August 5, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Wed, 05 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome for iOS

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-05T15:23:33.136Z

Reserved: 2026-07-27T23:36:59.109Z

Link: CVE-2026-17913

cve-icon Vulnrichment

Updated: 2026-08-05T15:23:27.743Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:55.450

Modified: 2026-08-10T14:14:40.423

Link: CVE-2026-17913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:00:10Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information