Executive brief
A vulnerability in the Cronet networking component of Google Chrome on Android could allow a remote attacker to perform domain spoofing. By using a specially crafted domain name, an attacker could trick users into believing they are visiting a legitimate website when they are actually on a malicious one. This could lead to phishing attacks where sensitive user information is stolen by impersonating trusted services.
Technical details
An inappropriate implementation vulnerability exists in Cronet, the network stack used by Google Chrome on Android. The flaw is triggered when the browser processes a specially crafted domain name, allowing a remote attacker to spoof the domain displayed to the user. This is categorized as a domain spoofing vulnerability where the root cause lies in how the component validates or renders specific character sets or domain structures. An attacker can exploit this by enticing a user to visit a malicious link, potentially bypassing security indicators. The issue is resolved in Google Chrome for Android version 149.0.7827.53.
Affected products
- Google Chrome for Android prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel.
- 2026-06-04: disclosed: CVE published.