CVE-2026-5895
vulnerability analysis and mitigation

Overview

CVE-2026-5895 is an incorrect security UI vulnerability in the Omnibox (URL bar) of Google Chrome on iOS that allows a remote attacker to spoof the displayed URL via a crafted domain name. It was reported by Renwa Hiwa (@RenwaX23) on October 18, 2024, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. All versions of Google Chrome on iOS prior to 147.0.7727.55 are affected. It carries a CVSS v3.1 base score of 5.4 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning the Omnibox component on iOS fails to correctly render or validate domain names, allowing a crafted domain to cause the URL bar to display misleading content. An attacker can exploit this remotely by directing a victim to a specially crafted URL or domain name that triggers the incorrect rendering in the iOS Chrome Omnibox. User interaction is required — the victim must visit the attacker-controlled page or link. The Chromium issue tracker references bug ID 374285495, though full technical details remain restricted pending broad user update (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to spoof the contents of the Chrome iOS Omnibox, making users believe they are visiting a legitimate website when they are actually on an attacker-controlled site. This primarily enables phishing attacks that can lead to credential theft, session hijacking, or malware distribution, as users may enter sensitive information trusting the displayed (spoofed) URL. The confidentiality and availability impacts are rated Low, with no direct integrity impact, and the vulnerability scope is limited to the affected browser instance (GitHub Advisory, Feedly).

Exploitation steps

  1. Craft a malicious domain: Register or control a domain name that, when processed by Chrome on iOS, causes the Omnibox to display a different (trusted-looking) domain due to the incorrect security UI handling.
  2. Deliver the link to the victim: Send the crafted URL to the target via phishing email, SMS, social media, or embed it in a webpage — any vector that causes the iOS Chrome user to navigate to the attacker's domain.
  3. Victim visits the page: When the user opens the link in Google Chrome on iOS (prior to 147.0.7727.55), the Omnibox displays a spoofed, legitimate-looking domain name instead of the actual attacker-controlled domain.
  4. Harvest credentials or deliver malware: The victim, trusting the displayed URL, may enter credentials, approve OAuth flows, or download files, enabling the attacker to steal sensitive information or distribute malicious content (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Outbound connections from iOS devices to suspicious or newly registered domains that visually resemble legitimate services (homograph/IDN-style domains).
  • Logs: Browser history or network proxy logs showing navigation to domains with unusual Unicode characters, punycode encoding, or atypical TLDs that mimic trusted brands.
  • User Reports: End-user reports of unexpected login prompts or credential requests on pages that appeared to show a trusted URL in the Chrome iOS address bar.

Mitigation and workarounds

Update Google Chrome on iOS to version 147.0.7727.55 or later, which contains the fix for this vulnerability (Chrome Releases). No configuration-based workaround is available; patching is the only remediation. Organizations should enforce automatic Chrome updates on managed iOS devices via MDM policies and educate users to be cautious of unexpected login prompts even when the URL bar appears to show a trusted domain.

Community reactions

The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity fixes in the update. The vulnerability itself, rated Low severity by Google, did not generate significant standalone commentary, though it was noted as part of a large batch of 60+ security fixes in Chrome 147 (GBHackers, BeyondMachines).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management