CVE-2026-13842: Chrome iOS Omnibox Spoofing Vulnerability – Patch Guidance
Google Chrome for iOS versions prior to 150.0.7871.47 contain a flaw that allows attackers to trick users by forging what appears in the browser's address bar (Omnibox). An attacker can craft a deceptive HTML page that makes it look like you're visiting a legitimate website when you're actually on a malicious one. This is a spoofing vulnerability—the attacker doesn't gain access to your data or crash your device, but can deceive you about where you actually are on the web.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-451
- Affected products
- 2 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-01
NVD description (verbatim)
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-13842 stems from an inappropriate implementation in Chrome's iOS rendering engine affecting the Omnibox UI component. The vulnerability allows remote attackers to manipulate the display of the URL bar via a crafted HTML page, creating a mismatch between the actual navigation target and what the user perceives as their destination. This is classified as an improper input validation and output encoding issue (CWE-451: User Interface (UI) Misrepresentation of Critical Information). The vulnerability requires user interaction to trigger—specifically, the user must visit or be directed to the attacker's malicious page. No authentication is required, and the attack surface is the open web.
Business impact
For iPhone users relying on Chrome as their primary browser, this vulnerability increases susceptibility to phishing and social engineering attacks. Users may be tricked into entering credentials, payment information, or other sensitive data on what they believe is a trusted website. Organizations with BYOD policies or employees using personal iPhones should be aware that this weakness reduces the reliability of visual trust indicators. The spoofing does not lead to data exfiltration or device compromise directly, but enables downstream attacks that do. Reputation risk exists if users attribute credential theft to an organization's website when the fault lies with a spoofed Omnibox.
Affected systems
The vulnerability affects Google Chrome on iOS running version 150.0.7871.46 and earlier. Apple iPhone OS devices that use Chrome as a browser are in scope. Note that Chrome on iOS uses WebKit rendering per Apple's requirements, which may influence the technical details of the flaw and patch scope. Desktop Chrome versions and Chrome on Android are not affected by this particular issue.
Exploitability
Exploitability is straightforward from an attacker's perspective: they craft a malicious HTML page and distribute it via phishing links, ads, or social engineering. No special privileges, zero-day chains, or advanced techniques are required. The barrier to exploitation is user interaction—the victim must navigate to the attacker's page. The CVSS score of 4.3 (MEDIUM, with Integrity impact only) reflects this: the attack is network-based with low complexity, requires user action, and causes deception rather than confidentiality or availability harm. This is not currently tracked in CISA's Known Exploited Vulnerabilities (KEV) catalog, suggesting no active in-the-wild exploitation has been publicly disclosed as of the publication date.
Remediation
The primary remediation is to update Google Chrome on iOS to version 150.0.7871.47 or later. Users should enable automatic app updates in iOS Settings > [App Name] > App Store, or manually check the App Store for Chrome updates. Organizations managing iOS devices via MDM should push the latest Chrome version to enrolled devices. No workarounds exist; patching is the only reliable mitigation. Until patching is complete, users should apply extra scrutiny to URL bar contents before entering sensitive information, though this places the burden on user vigilance rather than the system.
Patch guidance
Update Google Chrome for iOS to version 150.0.7871.47 or later. On individual devices, open the App Store, navigate to your profile, scroll to 'Available Updates,' and update Chrome if listed. For managed environments, use your MDM solution (Intune, Jamf, etc.) to enforce the minimum version via app configuration policies or app protection policies. Verify the update by opening Chrome, visiting Settings > About Chrome, and confirming the version number exceeds 150.0.7871.46. Rollout should prioritize users in high-risk roles (finance, HR, customer-facing) and any users who have reported phishing attempts.
Detection guidance
Detection at the endpoint level is limited because Omnibox spoofing is a rendering artifact visible only to the user. Network-based detection could flag unusual navigation patterns to attacker-controlled domains if the malicious site is already known, but that presupposes threat intelligence on the specific page. Organizations should focus on detection of downstream indicators: unusual credential use, failed login attempts to trusted services with correct passwords (suggesting users were phished), or suspicious email forwarding rules set up post-infection. Monitor for Chrome version compliance via MDM reporting. User training to report suspicious URL bar behavior is a practical detective control.
Why prioritize this
Although the CVSS score is MEDIUM (4.3) and the vulnerability does not enable data theft or code execution directly, Omnibox spoofing is a high-confidence stepping stone for phishing and credential compromise. The ease of exploitation, broad user base, and direct enabling of social engineering justify prompt patching. Organizations with strict security postures should treat this as a priority because user deception scales rapidly in attacks. It is not a zero-day or emergency-level flaw, but it should not be deprioritized behind purely technical vulnerabilities. The lack of active exploitation reduces urgency compared to KEV-tracked flaws, making this appropriate for a standard monthly patch cycle rather than emergency response.
Risk score, explained
The CVSS v3.1 score of 4.3 is driven by: (1) Network attack vector (AV:N) — remote delivery via the web; (2) Low attack complexity (AC:L) — no special conditions or tools needed; (3) No privilege requirement (PR:N) — unauthenticated attacker; (4) User interaction required (UI:R) — victim must visit the page; (5) Unchanged scope (S:U) — no privilege escalation; (6) Low integrity impact (I:L) — deception but not direct data loss or modification; (7) No confidentiality or availability impact (C:N/A:N). This places it in the MEDIUM severity band. The score accurately reflects the nature of the flaw: accessible and easy to exploit, but limited in direct harm scope. Environmental factors (e.g., prevalence of Chrome on iOS in your user base) may warrant local elevation of risk perception.
Frequently asked questions
Can an attacker steal my passwords if they spoof the Omnibox?
Not directly through the vulnerability itself. However, by making you believe you are on a legitimate website (e.g., your bank's login page), they can trick you into entering your credentials into a fake form. This is a phishing attack enabled by the spoofing flaw. The vulnerability is the deception tool; the attacker still needs your voluntary input of secrets.
Does this vulnerability affect Chrome on my Android phone or desktop?
No. This flaw is specific to Chrome on iOS due to how Chrome implements the Omnibox on Apple's platform. Android and desktop Chrome versions prior to 150.0.7871.47 are not affected by this particular issue, though they may have other vulnerabilities addressed in that same release.
What should I do if I've already clicked on a suspicious link in Chrome on iOS?
First, update your Chrome app to version 150.0.7871.47 or later to prevent future spoofing. Then review your accounts for unauthorized activity—check login history, password changes, and any forwarding rules set on email or messaging services. If you suspect you entered credentials, consider changing passwords for sensitive accounts from a trusted device. Monitor for phishing and credential stuffing attempts in the coming weeks.
Is there a temporary fix while waiting for the patch to roll out?
There is no technical workaround. Your mitigation is awareness: be extra cautious about URL bar contents before entering any sensitive information, and verify website authenticity through other means (e.g., calling the company directly, using bookmarks instead of links). However, this places the burden on you rather than the system. Patching is the reliable solution.
This analysis is provided for informational purposes and reflects the state of knowledge as of the publication date. CVSS scores, vendor advisories, and patch version numbers are sourced from official security databases and vendor disclosures. Organizations should verify patch applicability in their own environment and test updates before broad deployment. User training and incident response procedures should be in place to handle any phishing attempts that exploit this or similar flaws. SEC.co makes no warranty regarding the completeness or accuracy of remediation guidance and recommends consultation with vendor documentation and your own security team before taking action. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-11107MEDIUMGoogle Chrome UI Spoofing Vulnerability – Patch Guide
- CVE-2026-11216MEDIUMChrome File Input UI Spoofing – Patch to 149.0.7827.53
- CVE-2026-11222MEDIUMChrome Tab Strip Domain Spoofing Vulnerability – Patch Guide
- CVE-2026-11225MEDIUMChrome Domain Spoofing Vulnerability – Patch Guidance
- CVE-2026-11227MEDIUMChrome Tab Hover Card Domain Spoofing Vulnerability
- CVE-2026-11228MEDIUMChrome UI Spoofing Vulnerability via File Input Flaw
- CVE-2026-11232MEDIUMGoogle Chrome TabGroups UI Spoofing Vulnerability
- CVE-2026-11245MEDIUMChrome UI Spoofing in Payments Component (CVSS 4.3)