Executive brief
Google Chrome's URL formatting component contains a flaw that allows attackers to trick users into visiting malicious websites by disguising the actual domain in the address bar. By using carefully crafted domain names combined with social engineering, an attacker can spoof the browser's address bar, making it appear as though the user is visiting a legitimate site when they are actually on an attacker-controlled domain. This could lead to credential theft, account takeover, or malware infection if users are deceived into performing actions they believe are on trusted sites.
Technical details
This is a UI misrepresentation vulnerability in Chrome's UrlFormatting component that allows domain spoofing attacks. An attacker can craft a malicious domain name that, when rendered in Chrome's address bar, appears to represent a different (legitimate) domain due to improper formatting or display logic. The attack requires user interaction—specifically social engineering to trick the user into clicking a link to the malicious domain—but does not require authentication or special network positioning. Successful exploitation allows the attacker to visually deceive users into believing they are on a trusted website while actually viewing attacker-controlled content. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched