Description
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome for iOS displays an incorrect security UI for sites, allowing a remote attacker to craft an HTML page that causes users to see a spoofed warning or dialog. This vulnerability gives attackers the ability to impersonate legitimate security prompts. The primary impact is deception of users into divulging sensitive information or performing unintended actions, undermining confidentiality of user credentials and potentially leading to financial loss or credential compromise.

Affected Systems

The issue affects Google Chrome on iOS devices running any version prior to 151.0.7922.72. Versions 151.0.7922.72 and later contain the fix. Only the iOS builds of Chrome are impacted; other platforms are not affected.

Risk and Exploitability

The CVSS score of 4.3 classifies the vulnerability as low severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, where the attacker hosts a malicious web page that users load, thereby triggering the spoofed UI. Because it requires the user to visit the crafted page, exploitation depends on user interaction rather than a purely technical attack.

Generated by OpenCVE AI on August 3, 2026 at 11:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on iOS to version 151.0.7922.72 or later, as released in the July 2026 stable channel update.
  • Keep the Chrome application set to automatically update and ensure that the Safe Browsing feature is enabled to help mitigate malicious site exploitation.
  • Provide end‑users with training on recognizing legitimate security warnings in Chrome and advise them not to enter sensitive information if the UI does not match the expected secure indicator.
  • For managed devices, enforce Chrome policy settings that prevent installation of older versions and require automatic updates.

Generated by OpenCVE AI on August 3, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Mon, 03 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Incorrect Security UI in Chrome for iOS

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T19:16:27.859Z

Reserved: 2026-07-27T23:37:09.609Z

Link: CVE-2026-17965

cve-icon Vulnrichment

Updated: 2026-07-30T19:14:20.994Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:17:00.990

Modified: 2026-08-03T19:06:33.163

Link: CVE-2026-17965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:45:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information