Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)
https://issues.chromium.org/issues/379818904
https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.html