Executive brief
Chrome's CustomTabs feature on Android allows users to open web content in a secure browser context. A vulnerability in this feature enables remote attackers to spoof the address bar, making it difficult for users to verify the actual website they're visiting. This could allow attackers to deceive users into entering credentials or personal information on fake websites.
Technical details
This vulnerability is a UI misrepresentation flaw in Chrome's CustomTabs component on Android. An attacker can craft a malicious HTML page that, when loaded, displays a fraudulent address bar, misleading users about the true origin of the content they are viewing. The attack requires only network access and user interaction (visiting a crafted URL), but does not require authentication. The vulnerability was patched in Chrome 152.0.7977.65 and later versions. Chromium rated this as Low severity, though it has been assigned a CVSS score of 4.3 (medium).
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65