Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-13916

CVE-2026-13916: Chrome for iOS XSS Vulnerability

CVE-2026-13916 is a cross-site scripting flaw in Chrome for iOS allowing UI spoofing via crafted HTML pages. This article covers technical details, affected versions prior to 150.0.7871.47, and mitigation steps.

Published:

CVE-2026-13916 Overview

CVE-2026-13916 is a user interface (UI) spoofing vulnerability in Google Chrome for iOS versions prior to 150.0.7871.47. The flaw stems from an inappropriate implementation in Chrome for iOS that allows a remote attacker to spoof browser UI elements through a crafted HTML page. Google classifies the Chromium security severity as Medium. The vulnerability maps to CWE-451: User Interface (UI) Misrepresentation of Critical Information.

Exploitation requires user interaction, such as visiting an attacker-controlled web page. Successful exploitation can mislead users about the origin or trustworthiness of displayed content, enabling phishing and credential theft scenarios.

Critical Impact

A remote attacker can spoof legitimate browser UI elements on iOS devices, tricking users into trusting malicious content and disclosing sensitive information.

Affected Products

  • Google Chrome for iOS prior to 150.0.7871.47
  • Chromium-based browser components on iOS shipping this Chrome version
  • iOS devices running vulnerable Chrome builds

Discovery Timeline

  • 2026-06-30 - CVE-2026-13916 published to the National Vulnerability Database (NVD)
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2026-13916

Vulnerability Analysis

The vulnerability resides in Chrome for iOS and involves inappropriate handling of UI rendering when processing crafted HTML content. A remote attacker who convinces a user to visit a malicious page can manipulate visible browser UI elements to misrepresent the true origin or state of displayed content.

UI spoofing flaws in mobile browsers are particularly effective because screen real estate is limited and address bar behavior differs from desktop browsers. Attackers commonly leverage these primitives to imitate legitimate login prompts, security indicators, or origin displays. The result is that a victim can believe they are interacting with a trusted site when they are not.

The attack does not require authentication and can be delivered over the network. Impact is limited to integrity of information presented to the user; confidentiality of browser data and availability of the browser are not directly affected by the flaw itself.

Root Cause

The root cause is an inappropriate implementation in Chrome for iOS that permits crafted HTML to influence UI elements in ways the browser's security model does not intend. Under CWE-451, the browser fails to consistently render security-critical UI so that users can distinguish attacker-controlled content from legitimate browser chrome.

Attack Vector

Exploitation follows a standard drive-by pattern. An attacker hosts a crafted HTML page and lures a Chrome for iOS user to visit it through phishing, malvertising, or an embedded link. Once the page loads, the crafted content triggers the UI spoofing behavior, presenting misleading indicators to the user. The attacker then relies on the deceived user to enter credentials, approve a prompt, or take other actions that benefit the attacker.

Technical details are tracked in the Chromium Issue Tracker #508283108 and disclosed in the Google Chrome Desktop Update advisory.

Detection Methods for CVE-2026-13916

Indicators of Compromise

  • Chrome for iOS clients reporting a version string lower than 150.0.7871.47 in browser telemetry or mobile device management (MDM) inventory.
  • User reports of address bar or origin indicators that do not match the domain being visited.
  • Phishing pages served with unusual layered iframe, overlay, or full-viewport rendering targeting mobile Safari WebKit engines.

Detection Strategies

  • Correlate MDM version data with the fixed build 150.0.7871.47 to identify vulnerable Chrome for iOS installations across the fleet.
  • Inspect web proxy and DNS logs for user visits to newly registered or low-reputation domains hosting HTML pages that mimic corporate login portals.
  • Monitor authentication systems for credential submissions originating from mobile Chrome user agents shortly after visits to untrusted domains.

Monitoring Recommendations

  • Track Chrome for iOS version distribution over time and alert when devices remain below 150.0.7871.47 after the patch window.
  • Enrich phishing telemetry with the mobile browser and operating system identifiers to prioritize investigation of iOS Chrome sessions.
  • Feed URL reputation and threat intelligence into mobile secure web gateway policies to block suspected UI spoofing lures at the network layer.

How to Mitigate CVE-2026-13916

Immediate Actions Required

  • Update Google Chrome for iOS to version 150.0.7871.47 or later on all managed and personal devices.
  • Push the update through the MDM or unified endpoint management (UEM) platform and enforce compliance for corporate iOS devices.
  • Communicate to users that mobile browser UI, including the address bar, must be verified before entering credentials on any site.

Patch Information

Google addressed CVE-2026-13916 in Chrome for iOS build 150.0.7871.47. Users should install the update through the Apple App Store. Details of the release are available in the Chrome Releases blog, and the underlying fix is tracked in Chromium Issue #508283108.

Workarounds

  • Use an alternative up-to-date browser on iOS until Chrome for iOS can be updated to 150.0.7871.47.
  • Restrict access to untrusted websites from iOS Chrome using MDM-enforced content filtering or a mobile secure web gateway.
  • Reinforce phishing-resistant authentication such as FIDO2 security keys or platform passkeys so that spoofed prompts cannot yield reusable credentials.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.