Description
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: UI Spoofing
Action: Patch Immediately
AI Analysis

Impact

An incorrectly implemented security UI in the omnibox of Google Chrome on iOS allows a remote attacker to manipulate the user interface through a specially crafted web page. This flaw can cause users to see a false or misleading security indicator, leading them to believe that a page is secure when it is not. The vulnerability originates from the flawed presentation layer rather than a flaw in underlying security functions, which is why the Chromium Security team classifies it as low severity.

Affected Systems

Google Chrome on iOS versions prior to 147.0.7727.55 are affected. The issue exists in the omnibox component, which is the combined address and search bar that appears on the browser's home screen. All iOS devices running versions of Chrome below the mentioned update are vulnerable until they receive the official patch.

Risk and Exploitability

The attack vector is likely remote, requiring the user to visit a malicious web page that contains the crafted content. Although the CVSS score is not provided, the vulnerability is considered low risk by Chromium. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited public exploitation. Nevertheless, an attacker could use this UI deception to phish credentials or user behavior, so remediation is advised.

Generated by OpenCVE AI on April 8, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on all iOS devices to version 147.0.7727.55 or newer.
  • Verify that the update is successfully applied before visiting untrusted sites.

Generated by OpenCVE AI on April 8, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS Omnibox UI Spoofing Vulnerability
First Time appeared Google
Google chrome
Weaknesses CWE-200
CWE-795
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:58.284Z

Reserved: 2026-04-08T19:34:42.491Z

Link: CVE-2026-5898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:29.690

Modified: 2026-04-08T22:16:29.690

Link: CVE-2026-5898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:20Z

Weaknesses