I have bad news for you. Phishing attacks do not even need a fake browser UI. Even if XFS attacks are almost all fixed today, you don't need an iframe: there are fake versions of thousands of websites out there, and some tools can automate this faking process while adapting to user language, OS, etc.