Google Chrome Omnibox Spoofing Vulnerability on Android

Vulnerability

A vulnerability in the Omnibox component of Google Chrome for Android, in versions prior to 141.0.7390.54, allowed remote attackers to spoof the contents of the Omnibox (URL bar) by using a crafted HTML page. This issue was due to inappropriate implementation within the Omnibox.

Impact

Exploitation of this vulnerability could lead to misleading users about the URL they are viewing, potentially facilitating phishing attacks or other forms of deception.

Remediation

Users can update to Google Chrome version 141.0.7390.54 or later to address this vulnerability.

Added: Nov 6, 2025, 10:34 PM
Updated: Nov 6, 2025, 10:34 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.