Executive brief
Google Chrome's CustomTabs feature on Android contains a user interface flaw that allows a malicious co-installed app to spoof the browser address bar, deceiving users about which website they are visiting. This could facilitate phishing attacks or social engineering by making fraudulent pages appear to come from legitimate domains.
Technical details
This vulnerability is a UI misrepresentation (also called a "spoofing" or "UI redressing" vulnerability) in the CustomTabs component of Chrome on Android. A co-installed app can exploit this flaw to display a fake address bar, allowing it to trick users into believing they are on a legitimate website when they are actually on an attacker-controlled page. The attack requires local presence (a co-installed malicious app) but does not require elevated privileges or user interaction beyond visiting a spoofed page. Google fixed this issue in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 and later