Junglewise Threat Intelligence

CVE-2026-17794: Google Chrome for Android Omnibox spoofing via improper input validation

CVE-2026-17794 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Android could allow a malicious website to fake the address shown in the browser's URL bar. This type of flaw is typically used in phishing attacks to trick users into believing they are on a legitimate website, such as a bank or login portal, when they are actually on a site controlled by an attacker. To exploit this, an attacker would first need to compromise a specific internal browser process or lure a user to a specially crafted webpage.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Mobile component of Google Chrome for Android. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to spoof the contents of the Omnibox (URL bar). This allows the attacker to display a fraudulent URL while the browser is actually visiting a different, potentially malicious site. The vulnerability is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats