
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5895 is an incorrect security UI vulnerability in the Omnibox (URL bar) of Google Chrome on iOS that allows a remote attacker to spoof the displayed URL via a crafted domain name. It was reported by Renwa Hiwa (@RenwaX23) on October 18, 2024, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. All versions of Google Chrome on iOS prior to 147.0.7727.55 are affected. It carries a CVSS v3.1 base score of 5.4 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning the Omnibox component on iOS fails to correctly render or validate domain names, allowing a crafted domain to cause the URL bar to display misleading content. An attacker can exploit this remotely by directing a victim to a specially crafted URL or domain name that triggers the incorrect rendering in the iOS Chrome Omnibox. User interaction is required — the victim must visit the attacker-controlled page or link. The Chromium issue tracker references bug ID 374285495, though full technical details remain restricted pending broad user update (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to spoof the contents of the Chrome iOS Omnibox, making users believe they are visiting a legitimate website when they are actually on an attacker-controlled site. This primarily enables phishing attacks that can lead to credential theft, session hijacking, or malware distribution, as users may enter sensitive information trusting the displayed (spoofed) URL. The confidentiality and availability impacts are rated Low, with no direct integrity impact, and the vulnerability scope is limited to the affected browser instance (GitHub Advisory, Feedly).
Update Google Chrome on iOS to version 147.0.7727.55 or later, which contains the fix for this vulnerability (Chrome Releases). No configuration-based workaround is available; patching is the only remediation. Organizations should enforce automatic Chrome updates on managed iOS devices via MDM policies and educate users to be cautious of unexpected login prompts even when the URL bar appears to show a trusted domain.
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity fixes in the update. The vulnerability itself, rated Low severity by Google, did not generate significant standalone commentary, though it was noted as part of a large batch of 60+ security fixes in Chrome 147 (GBHackers, BeyondMachines).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."