PT-2026-31513 · Google · Google Chrome

Renwa Hiwa

+1

·

Published

2024-10-18

·

Updated

2026-05-29

·

CVE-2026-5895

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Google Chrome for iOS versions prior to 147.0.7727.55
Description An incorrect security user interface issue in the Omnibox (the browser's address bar) allows a remote attacker to spoof the contents of the URL bar. This is achieved by using a specially crafted domain name, specifically utilizing two Right-to-Left (RTL) Arabic character subdomains to mislead the user.
Recommendations Update Google Chrome for iOS to version 147.0.7727.55 or later.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2026-04985
CVE-2026-5895
OPENSUSE-SU-2026:10530-1
OPENSUSE-SU-2026:20575-1

Affected Products

Google Chrome