A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-11285

CVE-2026-11285: Google Chrome XSS Vulnerability

CVE-2026-11285 is a cross-site scripting flaw in Google Chrome for iOS that enables UI spoofing through malicious HTML pages. This article covers the technical details, affected versions, security impact, and mitigation.

Published: June 12, 2026

CVE-2026-11285 Overview

CVE-2026-11285 affects Google Chrome for iOS versions prior to 149.0.7827.53. The flaw stems from an inappropriate implementation in the Chrome for iOS browser, allowing a remote attacker to perform user interface (UI) spoofing through a crafted HTML page. Google classifies the issue as a low severity Chromium defect, while NVD scores it as medium based on its network attack vector and user interaction requirement. The vulnerability maps to [CWE-451] (User Interface Misrepresentation of Critical Information), a class of bugs commonly leveraged in phishing campaigns. Successful exploitation requires the victim to visit an attacker-controlled web page.

Critical Impact

Attackers can spoof browser UI elements in Chrome for iOS to deceive users into trusting malicious content, enabling phishing and credential theft.

Affected Products

  • Google Chrome for iOS versions prior to 149.0.7827.53
  • Apple iPhone OS (as the underlying platform)
  • Any iOS device running a vulnerable Chrome build

Discovery Timeline

  • 2026-06-05 - CVE-2026-11285 published to NVD
  • 2026-06-09 - Last updated in NVD database

Technical Details for CVE-2026-11285

Vulnerability Analysis

The vulnerability resides in how Chrome for iOS renders certain UI components when processing crafted HTML content. An attacker can construct a web page that manipulates browser chrome elements, such as the address bar, security indicators, or modal dialogs, to misrepresent the origin or trust state of displayed content. This class of issue is tracked under [CWE-451], which covers misleading representation of security-critical information in user interfaces.

The flaw affects only the iOS variant of Chrome, which runs on top of Apple's WebKit engine due to App Store platform requirements. Chrome on iOS therefore inherits constraints distinct from desktop or Android Chrome builds. The inappropriate implementation likely involves how URL bar updates or overlay rendering interact with attacker-controlled DOM content during navigation events.

Root Cause

The root cause is an inappropriate implementation in the Chrome for iOS UI handling logic. The browser fails to enforce a clear separation between trusted browser-rendered indicators and untrusted page content under specific conditions. This allows a crafted HTML page to influence what the user perceives as authentic browser UI.

Attack Vector

The attack requires no privileges and no authentication. A victim must visit a malicious web page or follow a crafted link, satisfying the user interaction requirement. Once loaded, the page renders elements that overlay or mimic legitimate Chrome UI, leading the user to make security decisions based on falsified information. The Exploit Prediction Scoring System (EPSS) ranks active exploitation likelihood as low, consistent with the limited impact scope of UI spoofing flaws.

No verified proof-of-concept code is publicly available. See the Chromium Issue Tracker Entry and the Google Chrome Update Announcement for vendor technical details.

Detection Methods for CVE-2026-11285

Indicators of Compromise

  • Chrome for iOS clients reporting version strings below 149.0.7827.53 in telemetry or user-agent logs.
  • User reports of inconsistent or misleading address bar content, particularly during redirects to credential entry pages.
  • Outbound traffic to newly registered domains hosting HTML payloads that mimic financial, enterprise, or single sign-on portals.

Detection Strategies

  • Inventory mobile fleet Chrome versions through mobile device management (MDM) reporting and flag installations below the patched build.
  • Monitor web proxy and DNS logs for users navigating to phishing-style landing pages immediately after clicking links from email or messaging applications.
  • Correlate user-reported phishing incidents with browser version data to surface iOS users who may have been targeted.

Monitoring Recommendations

  • Enable URL filtering and reputation-based blocking on mobile network egress points.
  • Track authentication anomalies, such as unfamiliar geolocations or impossible-travel events, that may indicate credentials harvested via spoofed UI.
  • Maintain phishing simulation programs that include mobile browser scenarios to measure user susceptibility to UI deception.

How to Mitigate CVE-2026-11285

Immediate Actions Required

  • Update Google Chrome for iOS to version 149.0.7827.53 or later through the Apple App Store.
  • Push the update through mobile device management policies to enforce compliance across managed fleets.
  • Notify users about the risk of UI spoofing and reinforce verification habits for sensitive transactions performed in mobile browsers.

Patch Information

Google released the fix in Chrome for iOS 149.0.7827.53. Patch details are referenced in the Google Chrome Update Announcement and the Chromium Issue Tracker Entry. No vendor workaround substitutes for the official update.

Workarounds

  • Restrict mobile browsing to vetted applications and use enterprise browsers with strict URL display policies until the patch is applied.
  • Configure conditional access policies that require strong multi-factor authentication, reducing the impact of credentials phished through spoofed UI.
  • Train users to validate URLs through long-press preview on iOS and to avoid entering credentials from links received in email or messaging apps.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeXSS

  • Vendor/TechGoogle Chrome

  • SeverityMEDIUM

  • CVSS Score4.3

  • EPSS Probability0.03%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityLow
  • AvailabilityNone
  • CWE References
  • CWE-451
  • Technical References
  • Google Chrome Update Announcement

  • Chromium Issue Tracker Entry
  • Related CVEs
  • CVE-2026-11666: Google Chrome XSS Vulnerability

  • CVE-2026-11294: Google Chrome XSS Vulnerability

  • CVE-2026-11701: Google Chrome XSS Vulnerability

  • CVE-2026-11286: Google Chrome XSS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English