Executive brief
Google Chrome on Android contains a vulnerability in the password field UI that allows attackers to spoof security indicators through a crafted web page. An attacker could trick users into entering credentials on a fake login interface that appears legitimate, potentially leading to credential theft and account compromise.
Technical details
The vulnerability is a UI misrepresentation flaw in Chrome's password management UI on Android that allows remote attackers to spoof UI elements via a crafted HTML page. The attack requires user interaction (visiting a malicious webpage) and network connectivity. An attacker can create a fake login interface that mimics the genuine Chrome password field, deceiving users into entering their credentials. The vulnerability was patched in Chrome version 153.0.8010.36 and later. Google assigned this a "Low" severity rating in their internal Chromium assessment.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched