Executive brief
Google Chrome's fullscreen mode contained a UI spoofing vulnerability that allowed attackers to trick users into thinking they were visiting a legitimate website by forging the address bar display. A remote attacker could craft a malicious HTML page that, when opened in fullscreen, would hide or misrepresent the true URL, potentially leading users to enter credentials or sensitive information on fraudulent pages while believing they were on legitimate sites.
Technical details
This is a UI misrepresentation vulnerability in Google Chrome's fullscreen mode implementation. The vulnerable component fails to properly display or protect the address bar when content is rendered in fullscreen, allowing an attacker to craft malicious HTML that obscures or spoofs the browser's address bar display. An attacker can initiate the attack via a crafted HTML page delivered over the network; no authentication or special user interaction beyond opening the page is required. By exploiting this flaw, an attacker can conduct phishing attacks by convincing users that a spoofed page is legitimate, potentially leading to credential theft or social engineering. The vulnerability was patched in Chrome version 152.0.7977.75 and later.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in Chrome 152.0.7977.75