Junglewise Threat Intelligence

CVE-2026-17860: Google Chrome for Android Omnibox spoofing via malicious file

CVE-2026-17860 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a local attacker to manipulate the address bar (Omnibox) using a malicious file. This type of flaw is typically used in phishing attacks to trick users into believing they are visiting a legitimate website when they are actually on a fraudulent one. Successful exploitation could lead to the theft of sensitive information like login credentials or financial data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Mobile component of Google Chrome for Android. The flaw allows a local attacker to spoof the Omnibox (URL bar) contents by providing a specially crafted malicious file. This bypasses the browser's intended UI protections, potentially facilitating phishing or social engineering attacks. The vulnerability is addressed in version 151.0.7922.72. Access to specific bug details is currently restricted by the Chromium team until a majority of users have updated.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats