Chrome · Omnibox
CVE-2026-5895
Logic Error in Omnibox
Overview
Low
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Changed Functions
| Function | Change | Notes |
|---|---|---|
ifios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.mm |
modified |
Files Changed
ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.hios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.mmios/chrome/browser/location_bar/ui_bundled/location_bar_view_controller.mm
Patch
From f545d50577ba5a72a89e1495293d5d4bc52b64a4 Mon Sep 17 00:00:00 2001 From: Ameur Hosni <[email protected]> Date: Wed, 18 Feb 2026 02:26:31 -0800 Subject: [PATCH] [IOS] Fix RTL URL component reordering in the location bar This change fixes a visual issue where URLs containing RTL characters (e.g., IDN with RTL scripts) would cause the Location Bar label to switch to RTL paragraph alignment. This resulted in the visual reversal of URL components, displaying the Top-Level Domain on the left instead of the right, which could be misleading regarding the site's actual domain authority. Before: https://screenshot.googleplex.com/5KFCzgU68rw3D4D After: https://screenshot.googleplex.com/zJ8fo6KTKNGDgiZ Fixed: 470395720,374285495 Change-Id: I33884fc685cb7f9a26c93d67167b4f5529cbb668 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7581320 Reviewed-by: Gauthier Ambard <[email protected]> Commit-Queue: Ameur Hosni <[email protected]> Cr-Commit-Position: refs/heads/main@{#1586307} --- diff --git a/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.h b/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.h index 0cccea9..26b1e25 100644 --- a/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.h +++ b/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.h @@ -43,6 +43,10 @@ // Sets the location label's text. - (void)setLocationLabelText:(NSString*)string; +// Sets the location label's text. `clipTail` indicates whether the label should +// truncate the tail or the head. +- (void)setLocationLabelText:(NSString*)string clipTail:(BOOL)clipTail; + // Sets the location label's text and styles it as if it were placeholder text. - (void)setLocationLabelPlaceholderText:(NSString*)string; diff --git a/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.mm b/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.mm index f9e5a44d..a32e0a0 100644 --- a/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.mm +++ b/ios/chrome/browser/location_bar/ui_bundled/location_bar_steady_view.mm @@ -429,11 +429,23 @@ } - (void)setLocationLabelText:(NSString*)string { - if ([self.locationLabel.text isEqualToString:string]) { - return; - } + [self setLocationLabelText:string clipTail:NO]; +} + +- (void)setLocationLabelText:(NSString*)string clipTail:(BOOL)clipTail { + // Use attributed text to force LTR direction for URLs, preventing RTL + // characters from messing up the visual order (e.g. IDN with RTL scripts). + NSMutableParagraphStyle* style = [[NSMutableParagraphStyle alloc] init]; + // https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/url_display_guidelines/url_display_guidelines.md#rtl + [style setBaseWritingDirection:NSWritingDirectionLeftToRight]; + [style setLineBreakMode:clipTail ? NSLineBreakByTruncatingTail + : NSLineBreakByTruncatingHead]; + + NSDictionary* attributes = @{NSParagraphStyleAttributeName : style}; + + self.locationLabel.attributedText = + [[NSAttributedString alloc] initWithString:string attributes:attributes]; self.locationLabel.textColor = self.colorScheme.fontColor; - self.locationLabel.text = string; [self updateAccessibility]; } diff --git a/ios/chrome/browser/location_bar/ui_bundled/location_bar_view_controller.mm b/ios/chrome/browser/location_bar/ui_bundled/location_bar_view_controller.mm index 2be6102f..056f6c9e 100644 --- a/ios/chrome/browser/location_bar/ui_bundled/location_bar_view_controller.mm +++ b/ios/chrome/browser/location_bar/ui_bundled/location_bar_view_controller.mm @@ -423,9 +423,7 @@ #pragma mark - LocationBarSteadyViewConsumer - (void)updateLocationText:(NSString*)string clipTail:(BOOL)clipTail { - [self.locationBarSteadyView setLocationLabelText:string]; - self.locationBarSteadyView.locationLabel.lineBreakMode = - clipTail ? NSLineBreakByTruncatingTail : NSLineBreakByTruncatingHead; + [self.locationBarSteadyView setLocationLabelText:string clipTail:clipTail]; } - (void)updateLocationIcon:(UIImage*)icon
Loading diff…
Original Bug Report
reported by [email protected]
Chrome iOS Address Bar Spoof Using 2 RTL (Arabic Characters) Subdomains
Security Bug
VERSION
Chrome Version: 130.0.6723.37 (Official Build) stable (64-bit) Operating System: iOS 18 on iPhone 16
REPRODUCTION CASE
- Using Chrome iOS open
https://xn--llb.login.wwww.accounts.google.com.xn--llb.pwr.wtf/
Expected Result
Address bar showing ە.login.wwww.accounts.google.com.ە.pwr.wtf/
Actual Result
Address Bar shows pwr.wtf.ە.ogin.wwww.accounts.google.com...
Details
The issue arises when using 2 RTL characters in different level subdomains and in between add a domain that we want to spoof. First we add a RTL character then any domain we want to spoof and in the end we add another RTL character that will confuse the address bar and mixes up the RTL LTR showing of the URL.
CREDIT INFORMATION
Reporter credit: Renwa Hiwa @RenwaX23
References
On This Page