Impact
The vulnerability allows a remote attacker to manipulate the visual presentation of the Omnibox, the URL bar in Chrome on Android. By serving a specially crafted HTML page, the attacker can cause the Omnibox to display misleading or forged information. This user‑interface deception can lead to users believing they are viewing a legitimate site when they are not, thereby increasing the risk of phishing attacks. The weakness is identified as an inadequate user interface presentation and a disclosure of information, aligning with CWE‑1021 and CWE‑451.
Affected Systems
Google Chrome users on Android devices with a Chrome build older than 147.0.7727.55 are affected. No other operating systems or Chrome builds are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate impact, while the EPSS score of less than 1 % shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to deliver a crafted web page to the victim, which will then be rendered in the browser’s Omnibox. The primary attack vector is remote via the web, and the attacker only needs to entice the user to load the page; no privileged access or local code execution is required.
OpenCVE Enrichment
Debian DSA