Impact
A crafted HTML page can be served to a victim using CustomTabs in Google Chrome on Android before version 152.0.7977.65. The navigation bar that normally shows the current host is displayed incorrectly, allowing a remote attacker to masquerade as a trusted site and thereby mislead or trick the user into taking a desired action. The impact is primarily the loss of visual integrity and an increased risk of social engineering, but no direct compromise of data or code execution is reported.
Affected Systems
Google Chrome for Android, all builds released before 152.0.7977.65 are affected. Devices that run an outdated version of Chrome, whether installed from the Google Play Store or a custom Android build, are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 and an EPSS score below 1% categorize the flaw as low severity. It is not listed in the CISA KEV catalog. Exploitation requires a remote adversary to deliver a specially crafted HTML page to the victim’s device, typically through a malicious app or a compromised website utilizing CustomTabs. The likely attack vector is remote, web-based content. Given the low severity, the risk of widespread exploitation is currently considered modest, but the potential for user deception remains a concern.
OpenCVE Enrichment
Debian DLA
Debian DSA