Executive brief
A security issue in Google Chrome for Android could allow a malicious website to misrepresent its true web address (domain spoofing). This occurs due to an error in how the browser displays security information in its user interface. If exploited, a user might believe they are interacting with a legitimate site when they are actually on a fraudulent one, potentially leading to phishing or the disclosure of sensitive information.
Technical details
A domain spoofing vulnerability exists in the User Interface (UI) component of Google Chrome for Android. The flaw stems from an incorrect implementation of security indicators, which can be manipulated by a remote attacker using a specially crafted HTML page. By exploiting this UI inconsistency, an attacker can deceive users about the origin of the content they are viewing. This is classified as a 'Low' severity issue by Chromium. The vulnerability is addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed