CVE-2026-17972 Overview
CVE-2026-17972 is a user interface (UI) spoofing vulnerability in Google Chrome for iOS versions prior to 151.0.7922.72. The flaw results from an inappropriate implementation in Chrome for iOS that allows a remote attacker to manipulate browser UI elements through a crafted HTML page. Chromium rates the security severity as Low. Successful exploitation lets an attacker misrepresent browser context to the user, which can support phishing or credential-theft workflows. The vulnerability requires the victim to visit an attacker-controlled or attacker-influenced page.
Critical Impact
Remote attackers can spoof UI elements in Chrome for iOS to mislead users, enabling phishing scenarios that appear to originate from trusted origins.
Affected Products
- Google Chrome for iOS prior to 151.0.7922.72
Discovery Timeline
- 2026-07-30 - CVE-2026-17972 published to NVD
- 2026-07-30 - Last updated in NVD database
Technical Details for CVE-2026-17972
Vulnerability Analysis
The vulnerability is a User Interface Confusion issue in Chrome for iOS. A crafted HTML page can influence how the browser renders trust-relevant UI elements. Attackers use this discrepancy to make malicious content appear legitimate. Chromium classifies the security severity as Low, reflecting the limited direct impact on confidentiality or integrity. The primary risk is user deception rather than direct code execution or data disclosure.
Root Cause
The root cause is an inappropriate implementation in Chrome for iOS UI rendering logic. Browser chrome elements do not accurately reflect the underlying page state when specific HTML content is served. The affected code path was corrected in Chrome for iOS 151.0.7922.72. Refer to the Chromium Issue Tracker Entry for implementation-level details once access is granted.
Attack Vector
Exploitation requires a remote attacker to deliver a crafted HTML page to a Chrome for iOS user. The user must load the page, typically through a link, embedded frame, or redirect. Once loaded, the crafted content manipulates UI indicators that users rely on to assess trust. The vulnerability does not require authentication and does not need elevated privileges. It also does not grant code execution on the device.
No verified public exploitation code is available. See the Google Chrome Update Announcement for vendor context.
Detection Methods for CVE-2026-17972
Indicators of Compromise
- No public indicators of compromise have been published for CVE-2026-17972.
- Suspicious inbound links directing iOS users to unfamiliar domains that mimic trusted brand experiences.
- User reports of Chrome for iOS URL bar or security indicator inconsistencies.
Detection Strategies
- Inventory Chrome for iOS installations across managed devices and flag versions below 151.0.7922.72.
- Monitor mobile device management (MDM) telemetry for Chrome for iOS version compliance.
- Correlate phishing report submissions with browser and version metadata to identify targeted user populations.
Monitoring Recommendations
- Track access patterns to newly registered domains from iOS user agents running outdated Chrome builds.
- Alert on credential submissions to unclassified domains originating from mobile Chrome sessions.
- Review help-desk tickets that reference unexpected browser prompts or address bar anomalies on iOS.
How to Mitigate CVE-2026-17972
Immediate Actions Required
- Update Chrome for iOS to version 151.0.7922.72 or later through the Apple App Store.
- Push forced update policies via MDM for managed iOS fleets.
- Communicate phishing awareness guidance to users who rely on Chrome for iOS.
Patch Information
Google addressed the flaw in Chrome for iOS 151.0.7922.72. See the Google Chrome Update Announcement for the official release notes and the Chromium Issue Tracker Entry for issue tracking.
Workarounds
- Use an alternate iOS browser that is not affected until the update is applied.
- Restrict navigation to untrusted links on managed iOS devices via MDM web content filtering.
- Reinforce user training to verify URLs and site certificates before submitting credentials.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

