Executive brief
Google Chrome is a widely used web browser for accessing the internet. A vulnerability in the browser's user interface could allow a malicious website to display a fake web address in the URL bar (Omnibox). This could be used in phishing attacks to trick users into believing they are on a legitimate site, such as a bank or email provider, when they are actually on a site controlled by an attacker.
Technical details
This vulnerability is classified as a User Interface (UI) Misrepresentation (CWE-451) due to insufficient policy enforcement in the browser's UI components. An attacker who has already compromised the renderer process can exploit this flaw by using a specially crafted HTML page to spoof the Omnibox (URL bar) content. This requires user interaction, typically in the form of visiting a malicious website. Successful exploitation allows the attacker to misrepresent the origin of the page, facilitating sophisticated phishing or social engineering attacks. The issue is resolved in Google Chrome version 147.0.7727.55.
Affected products
- Google Chrome Prior to 147.0.7727.55
Timeline
- 2025-06-14: other: Vulnerability reported to Chromium by anonymous researcher
- 2026-04-07: patched: Fixed in Chrome Stable Channel Update 147.0.7727.55
- 2026-04-08: disclosed: Public disclosure of CVE-2026-5880