Description
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing / Phishing
Action: Update
AI Analysis

Impact

A crafted HTML page can be served to a victim using CustomTabs in Google Chrome on Android before version 152.0.7977.65. The navigation bar that normally shows the current host is displayed incorrectly, allowing a remote attacker to masquerade as a trusted site and thereby mislead or trick the user into taking a desired action. The impact is primarily the loss of visual integrity and an increased risk of social engineering, but no direct compromise of data or code execution is reported.

Affected Systems

Google Chrome for Android, all builds released before 152.0.7977.65 are affected. Devices that run an outdated version of Chrome, whether installed from the Google Play Store or a custom Android build, are vulnerable.

Risk and Exploitability

The CVSS score of 4.3 and an EPSS score below 1% categorize the flaw as low severity. It is not listed in the CISA KEV catalog. Exploitation requires a remote adversary to deliver a specially crafted HTML page to the victim’s device, typically through a malicious app or a compromised website utilizing CustomTabs. The likely attack vector is remote, web-based content. Given the low severity, the risk of widespread exploitation is currently considered modest, but the potential for user deception remains a concern.

Generated by OpenCVE AI on August 27, 2026 at 19:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on Android to at least version 152.0.7977.65 to eliminate the address‑bar spoofing flaw.
  • If an immediate upgrade cannot be applied, restrict the use of CustomTabs to trusted applications or disable CustomTabs for content that has not been verified by the system.
  • Confirm that the Chrome installation originates from the official Google Play Store and has not been replaced or tampered with by a third‑party application.

Generated by OpenCVE AI on August 27, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Address Bar Spoofing in Chrome CustomTabs on Android
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Address Bar Spoofing in Chrome CustomTabs on Android

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T15:32:01.601Z

Reserved: 2026-08-25T06:12:07.334Z

Link: CVE-2026-79233

cve-icon Vulnrichment

Updated: 2026-08-27T15:31:53.567Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:17.527

Modified: 2026-08-27T19:07:43.383

Link: CVE-2026-79233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:15:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information