Executive brief
Google Chrome's CustomTabs feature on Android contains a UI spoofing vulnerability that allows attackers to disguise malicious content as legitimate browser elements. An attacker can craft a webpage that mimics Chrome's interface, potentially tricking users into entering credentials, downloading malware, or visiting phishing sites. This vulnerability requires social engineering but could lead to credential theft, account compromise, or malware installation on affected Android devices.
Technical details
The vulnerability is a UI misrepresentation flaw in CustomTabs, Chrome's feature for embedding web content in third-party applications. An attacker can create a specially crafted HTML page that spoofs Chrome's UI elements, including the address bar, security indicators, or other interface components. The attack requires user interaction (viewing the malicious page) but no authentication. The vulnerability affects Chrome versions prior to 152.0.7977.65 on Android. Google has patched this issue in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65