PT-2026-31513 · Google · Google Chrome
Renwa Hiwa
+1
·
Published
2024-10-18
·
Updated
2026-05-29
·
CVE-2026-5895
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Google Chrome for iOS versions prior to 147.0.7727.55
Description
An incorrect security user interface issue in the Omnibox (the browser's address bar) allows a remote attacker to spoof the contents of the URL bar. This is achieved by using a specially crafted domain name, specifically utilizing two Right-to-Left (RTL) Arabic character subdomains to mislead the user.
Recommendations
Update Google Chrome for iOS to version 147.0.7727.55 or later.
Fix
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome