Junglewise Threat Intelligence

CVE-2026-17964: Google Chrome for Android domain spoofing in UI

CVE-2026-17964 · Severity: info · CVSS 3.1 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious website to misrepresent its true web address (domain spoofing). This occurs due to an error in how the browser displays security information in its user interface. If exploited, a user might believe they are interacting with a legitimate site when they are actually on a fraudulent one, potentially leading to phishing or the disclosure of sensitive information.

Technical details

A domain spoofing vulnerability exists in the User Interface (UI) component of Google Chrome for Android. The flaw stems from an incorrect implementation of security indicators, which can be manipulated by a remote attacker using a specially crafted HTML page. By exploiting this UI inconsistency, an attacker can deceive users about the origin of the content they are viewing. This is classified as a 'Low' severity issue by Chromium. The vulnerability is addressed in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats