Executive brief
Google Chrome's address bar navigation can be spoofed by a remote attacker through a crafted HTML page, making it appear as though the user is visiting a different website than they actually are. This is a phishing vulnerability that could trick users into entering sensitive information on an attacker-controlled site while believing they are on a legitimate website.
Technical details
This vulnerability is a UI misrepresentation flaw in Chrome's Navigation component that allows address bar spoofing. The attack requires a remote attacker to craft a malicious HTML page and requires user interaction (the user must visit the crafted page). By exploiting this vulnerability, an attacker can manipulate the browser's address bar display to show a different URL than the one actually loaded, enabling phishing and social engineering attacks. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65