Junglewise Threat Intelligence

CVE-2026-5906: Google Chrome for Android Omnibox spoofing

CVE-2026-5906 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to display a fake web address in the browser's URL bar. This type of flaw is typically used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or login portal, when they are actually on a fraudulent page. Users are protected by updating their browser to the latest version.

Technical details

A vulnerability classified as User Interface (UI) Misrepresentation of Critical Information (CWE-451) exists in the Omnibox component of Google Chrome for Android. The flaw stems from incorrect security UI handling, which allows a remote attacker to spoof the contents of the URL bar by enticing a user to visit a specially crafted HTML page. This bypasses the visual trust indicators intended to verify the site's origin. The issue is resolved in version 147.0.7727.55 and later. Exploitation requires user interaction to navigate to the malicious site.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-13: disclosed: Reported to Chromium by mohamedhesham9173
  • 2026-04-07: patched: Fixed in stable channel update 147.0.7727.55
  • 2026-04-08: advisory: NVD publication date

References

Related threats