Executive brief
A vulnerability in the FullScreen component of Google Chrome for Android could allow a malicious website to spoof the browser's user interface. By tricking the browser into displaying a deceptive full-screen view, an attacker could potentially mislead users into providing sensitive information or interacting with malicious content that appears to be a legitimate part of the browser or a trusted site. This issue primarily impacts user trust and could be used as a component in phishing attacks.
Technical details
A UI spoofing vulnerability exists in the FullScreen implementation of Google Chrome for Android. The flaw stems from an inappropriate implementation that allows a remote attacker to manipulate the visual presentation of the browser interface using a specially crafted HTML page. An attacker could exploit this by enticing a user to visit a malicious website, which then triggers a full-screen state that obscures or mimics legitimate browser UI elements. This vulnerability is classified as Low severity by Chromium and is addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed