Impact
Google Chrome on Android implements CustomTabs to render web content inside third‑party apps. A flaw in versions before 153.0.8010.36 allows a remote attacker to alter the visual representation of the address bar through a co‑installed application. The affected UI may show a legitimate origin while the content comes from a malicious source, effectively spoofing the address bar. This weakness corresponds to CWE‑451, reflecting improper handling of user interface representation, and could facilitate phishing or credential theft.
Affected Systems
Android devices running Google Chrome prior to version 153.0.8010.36 are vulnerable. The flaw applies to any co‑installed application that employs the CustomTabs API to display content within the browser. No other Chrome versions or operating systems are affected according to the current data.
Risk and Exploitability
The CVSS score of 4.8 indicates low severity, and the EPSS score is <1%. It is inferred that a remote attacker would need to obtain a malicious app onto the victim’s device, which could occur via the Play Store or side‑load channels. Once installed, the app can launch CustomTabs with a forged address bar to trick the user. The lack of a KEV designation means there have been no confirmed real‑world exploits, but it is inferred that the attack surface remains significant for users who run outdated Chrome versions.
OpenCVE Enrichment
Debian DLA
Debian DSA