Impact
A crafted HTML page in full‑screen mode can cause Google Chrome on Android prior to 152.0.7977.75 to display a fake address bar, allowing a remote attacker to make a user believe they are visiting a legitimate site. The vulnerability does not compromise authentication or data integrity directly but creates a convincing display that can lead to phishing or credential theft. The weakness is classified as CWE‑451 (Information Exposure).
Affected Systems
Google Chrome browsers running on Android devices with versions older than 152.0.7977.75 are affected.
Risk and Exploitability
The risk level is Medium as indicated by Chromium’s severity rating. The vulnerability can be exploited by any remote attacker who manages to host a malicious webpage. The exploit requires no additional privileges beyond normal browsing; it relies on the full‑screen mode feature. Because EPSS data is unavailable and the issue is not listed in CISA’s KEV catalog, the likelihood of widespread exploitation is uncertain, but the impact on user trust is significant.
OpenCVE Enrichment