Executive brief
A security vulnerability in Google Chrome for Android could allow a malicious website to fake the address shown in the browser's URL bar. This type of flaw is typically used in phishing attacks to trick users into believing they are on a legitimate website, such as a bank or login portal, when they are actually on a site controlled by an attacker. To exploit this, an attacker would first need to compromise a specific internal browser process or lure a user to a specially crafted webpage.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Mobile component of Google Chrome for Android. A remote attacker who has already compromised the renderer process can exploit this flaw via a crafted HTML page to spoof the contents of the Omnibox (URL bar). This allows the attacker to display a fraudulent URL while the browser is actually visiting a different, potentially malicious site. The vulnerability is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date