MEDIUM 4.3

CVE-2026-13980: Chrome iOS UI Spoofing Vulnerability (CVSS 4.3)

Google Chrome for iOS versions before 150.0.7871.47 contain a flaw that allows attackers to trick users through misleading user interface elements. An attacker could craft a malicious webpage that, when visited, displays fake Chrome UI components—such as address bars or security indicators—to deceive users into believing they're interacting with legitimate browser elements. This is a spoofing vulnerability that relies on user interaction; attackers must convince someone to visit a crafted page, but no special user permissions or technical sophistication is required on the user's end.

Source data · NVD / CISA · public domain

CVSS
3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weaknesses (CWE)
CWE-451
Affected products
2 configuration(s)
Published / Modified
2026-06-30 / 2026-07-02

NVD description (verbatim)

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

2 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

The vulnerability stems from inappropriate implementation in Chrome's UI handling layer on iOS, classified under CWE-451 (User Interface (UI) Misrepresentation of Critical Information). The flaw allows remote attackers to spoof UI elements through a crafted HTML page without requiring elevated privileges or special conditions—only network accessibility and user interaction. The attack surface is the rendering engine's failure to properly distinguish between legitimate browser chrome and attacker-controlled page content, enabling visual deception that can facilitate phishing, credential theft, or malware distribution through social engineering.

Business impact

This vulnerability primarily impacts user trust and organizational security posture on iOS devices. For enterprises managing mobile fleets or BYOD environments, UI spoofing attacks can facilitate convincing phishing campaigns that bypass traditional security awareness training. Users may be tricked into entering credentials, authorizing sensitive actions, or downloading malware disguised as legitimate system prompts. While the technical severity is medium, the business impact derives from the ease of exploitation and the psychological component—attackers need only craft a webpage and social engineer users to visit it. For organizations with significant iOS user bases, this can translate to credential compromise, data exfiltration, and lateral movement into corporate systems.

Affected systems

The vulnerability affects Google Chrome on iOS running versions prior to 150.0.7871.47. Because Chrome on iOS runs within Apple's WebKit sandbox on iPhone OS, both the browser and underlying operating system versions matter for remediation scope. Organizations should inventory Chrome on iOS deployments across their user base, particularly in BYOD and mobile-first environments. The fix is browser-specific and does not require OS-level patching, though deployment must account for iOS app distribution mechanisms and user update adoption rates, which are often slower than desktop browser updates.

Exploitability

Exploitability is straightforward from a technical standpoint. The vulnerability requires no authentication, no special permissions, and no system configuration changes. The sole prerequisite is user interaction—specifically, visiting a malicious webpage. With a CVSS score of 4.3 (network-accessible, low attack complexity, user interaction required, low integrity impact), this sits in the low-to-medium exploitability range. The practical barrier is social engineering: attackers must convince users to visit the crafted page. This is commonly achieved through phishing email, compromised websites, malvertising, or social media links. Given the ubiquity of iOS browsers and the effectiveness of UI spoofing in phishing, exploitation likelihood in the wild is moderate to high despite the user interaction requirement.

Remediation

The primary remediation is to update Chrome for iOS to version 150.0.7871.47 or later. Organizations should communicate this update requirement to users through Mobile Device Management (MDM) tools, security alerts, and user-facing notifications. For BYOD environments, consider using MDM policy to enforce minimum Chrome version compliance or push updates automatically if your MDM platform supports it. Additionally, security awareness training should emphasize verifying URL authenticity and recognizing UI spoofing attempts, particularly given the visual nature of this attack vector. Monitor user reports of suspicious browser behavior or unusual prompts, as early detection of active spoofing campaigns can prevent mass compromise.

Patch guidance

Verify that your Chrome for iOS installation is running version 150.0.7871.47 or later by navigating to Chrome Settings > About Chrome (or equivalent in your version). iOS users can also enable automatic app updates via the App Store settings to ensure Chrome patches are deployed promptly. For enterprise MDM deployments, confirm that your Mobile Device Management configuration enforces minimum Chrome version requirements and that the push/notification for updates reaches your user base. Test the update in a small cohort before organization-wide rollout to ensure no regression with line-of-business applications. Because iOS app updates rely on App Store delivery and user acceptance, adoption timelines may lag desktop browsers by weeks; plan accordingly and monitor update metrics through your MDM console.

Detection guidance

Detection is challenging at the network level because the attack vector is a crafted HTML page indistinguishable from benign content. Focus detection efforts on user behavior and endpoint logs: (1) Monitor for unusual Chrome security alerts or user reports of 'fake' browser prompts; (2) If your MDM platform logs app versions, periodically scan for Chrome installations below version 150.0.7871.47; (3) Correlate Chrome crash logs or rendering errors with suspicious website visits; (4) Review user authentication logs for successful logins immediately following visits to untrusted or newly-visited domains, as this may indicate successful spoofing-facilitated phishing. Advanced organizations can use browser telemetry or endpoint detection and response (EDR) tools to flag anomalous webpage rendering behavior, though consumer-grade Chrome on iOS has limited logging. User reporting remains your strongest detection signal.

Why prioritize this

Despite a moderate CVSS score (4.3), this vulnerability merits timely remediation because: (1) it affects a widely-used consumer application with significant enterprise presence (iOS Chrome users span BYOD and corporate deployments); (2) exploitability is trivial—no sophisticated attack infrastructure is required, only a crafted webpage and social engineering; (3) the attack bypasses traditional security controls (firewalls, email gateways, endpoint detection) because it operates within the browser and relies on user psychology; (4) successful exploitation directly enables credential theft and account compromise, which have downstream organizational impact; (5) patch availability and low user friction for updates mean rapid remediation is achievable. Prioritize communication and enforcement within 2–4 weeks of release.

Risk score, explained

The CVSS 3.1 score of 4.3 (Medium) reflects the low barrier to attack delivery (network-accessible, low complexity), offset by the user interaction requirement and limited direct impact (integrity only, no confidentiality or availability breach). However, the score does not capture the business risk: this vulnerability is a vector for social engineering and credential compromise, which are high-impact outcomes in practice. Organizations should treat this as higher priority than the raw CVSS might suggest, weighing the ease of exploitation, the prevalence of iOS Chrome, and the organizational impact of phishing success. The 'Medium' tag is technically accurate for the UI spoofing itself, but the downstream risks (account takeover, data theft) elevate organizational priority.

Frequently asked questions

Can this vulnerability be exploited without user interaction?

No. The attack requires a user to visit a malicious webpage. There is no zero-click variant; an attacker cannot exploit this through background processes, push notifications, or automatic page loads alone. Users must actively navigate to or click a link to the crafted HTML page.

Does updating Chrome on iOS automatically protect me?

Yes, once you update Chrome for iOS to version 150.0.7871.47 or later, you are protected against this specific vulnerability. Enable automatic app updates in your iOS App Store settings to ensure future Chrome security patches install without manual intervention.

How is UI spoofing different from a typical phishing attack?

In traditional phishing, attackers create a fake website that mimics a legitimate service (e.g., a fake login page). UI spoofing goes further: it uses the rendering engine itself to overlay or mimic genuine browser UI elements—like the address bar or security indicators—within the webpage. This makes the attack more convincing because users see what appear to be legitimate browser controls, even though those controls are actually attacker-controlled content.

If I'm on iOS and don't use Chrome, should I be concerned?

No. This vulnerability is specific to Chrome for iOS. If you use Safari, Firefox, Edge, or another browser on your iPhone, you are not affected. However, if anyone in your organization uses Chrome on iOS, ensure they update to patch their devices.

This analysis is provided for informational and educational purposes. It is based on publicly available vulnerability data as of the publication date. While we have taken care to ensure accuracy, SEC.co makes no warranty regarding the completeness or timeliness of this information. Organizations should independently verify all patch versions, vendor advisories, and affected product lists against their deployed environments and the official vendor security releases. This vulnerability summary does not constitute professional security advice; consult your security team or a qualified cybersecurity professional for guidance specific to your infrastructure and risk posture. Patch deployment, testing, and prioritization should align with your organization's change management and incident response procedures. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).