Executive brief
Google Chrome on Android contains a UI spoofing vulnerability in fullscreen mode that allows attackers to craft malicious web pages which can hide or misrepresent the browser's address bar. This allows attackers to deceive users about which website they are visiting, potentially leading to phishing attacks or credential theft without the user's awareness.
Technical details
The vulnerability is a UI misrepresentation flaw in Chrome's fullscreen implementation on Android that permits address bar spoofing through a crafted HTML page. An unauthenticated remote attacker can leverage this by hosting a malicious webpage that, when accessed in fullscreen mode, hides or mimics the legitimate address bar, causing users to believe they are visiting a trusted site when they are actually on an attacker-controlled domain. The vulnerability affects Chrome versions prior to 152.0.7977.75 on Android. A patch is available in Chrome 152.0.7977.75 and later.
Affected products
- Google Chrome prior to 152.0.7977.75 on Android
Timeline
- 2026-09-02: disclosed