Description
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spoofed address bar can mislead users to enter credentials on a falsified site, creating phishing risk.
Action: Update Browser
AI Analysis

Impact

Google Chrome on Android implements CustomTabs to render web content inside third‑party apps. A flaw in versions before 153.0.8010.36 allows a remote attacker to alter the visual representation of the address bar through a co‑installed application. The affected UI may show a legitimate origin while the content comes from a malicious source, effectively spoofing the address bar. This weakness corresponds to CWE‑451, reflecting improper handling of user interface representation, and could facilitate phishing or credential theft.

Affected Systems

Android devices running Google Chrome prior to version 153.0.8010.36 are vulnerable. The flaw applies to any co‑installed application that employs the CustomTabs API to display content within the browser. No other Chrome versions or operating systems are affected according to the current data.

Risk and Exploitability

The CVSS score of 4.8 indicates low severity, and the EPSS score is <1%. It is inferred that a remote attacker would need to obtain a malicious app onto the victim’s device, which could occur via the Play Store or side‑load channels. Once installed, the app can launch CustomTabs with a forged address bar to trick the user. The lack of a KEV designation means there have been no confirmed real‑world exploits, but it is inferred that the attack surface remains significant for users who run outdated Chrome versions.

Generated by OpenCVE AI on September 9, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to 153.0.8010.36 or later, which includes the bug fix for CustomTabs UI rendering.
  • Enable automatic updates on Android and use Google Play Protect to prevent malicious co‑installed apps from exploiting the flaw.
  • If an immediate Chrome update is not possible, locate and uninstall any applications that use CustomTabs for internal navigation, or disable the CustomTabs feature in those apps’ settings if available.

Generated by OpenCVE AI on September 9, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 10 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Co‑installed App Enables Address Bar Spoofing via CustomTabs in Android Chrome

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Co‑installed App Enables Address Bar Spoofing via CustomTabs in Android Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof address bar via a co-installed app. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:41:22.837Z

Reserved: 2026-09-08T22:41:55.272Z

Link: CVE-2026-87597

cve-icon Vulnrichment

Updated: 2026-09-09T19:41:15.531Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:17.673

Modified: 2026-09-10T13:44:48.260

Link: CVE-2026-87597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T11:45:11Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information