Executive brief
Google Chrome on Android includes a feature called TrustedWebActivities that allows apps to display web content. A clickjacking vulnerability in this feature permits a malicious app installed alongside Chrome to spoof the address bar, deceiving users into believing they are visiting a legitimate website when they are actually on a fraudulent one. This could lead to credential theft, malware installation, or other social engineering attacks.
Technical details
The vulnerability is a clickjacking issue in Google Chrome's TrustedWebActivities feature on Android. A local attacker with the ability to install a co-installed app can exploit this flaw to spoof the browser's address bar, potentially tricking users into entering sensitive information or downloading malicious content. The vulnerability requires local access (co-installed app) and no user authentication, but does depend on social engineering to succeed. The issue is fixed in Chrome version 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36