
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0906 is an incorrect security UI vulnerability in Google Chrome on Android that allows a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. It was reported by Khalil Zhani on 2025-12-10 and publicly disclosed on January 13, 2026, when Google released Chrome 144. The vulnerability affects Google Chrome on Android prior to version 144.0.7559.59, and Microsoft Edge Chromium is also listed as an affected product. Google rated this as Low severity internally, though CISA-ADP assigned a CVSS v3.1 base score of 9.8 (Critical) — a score that appears inconsistent with the Low severity designation and limited impact scope described (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning the browser fails to accurately represent security-critical information to the user. Specifically, a remote attacker can craft a malicious HTML page that causes the Chrome Android Omnibox (address/URL bar) to display incorrect or spoofed content, misleading users about the true origin of the page they are viewing. This is an Android-specific issue, and exploitation requires a user to visit a specially crafted web page. No memory corruption or code execution is involved; the attack is purely a UI spoofing technique (Chrome Releases, Feedly).
Successful exploitation allows an attacker to spoof the URL bar on Chrome for Android, potentially deceiving users into believing they are on a legitimate website (e.g., a banking or authentication portal) when they are actually on a malicious page. This primarily enables phishing attacks and credential theft, as users may enter sensitive information trusting the spoofed URL. There is no direct impact on confidentiality, integrity, or availability of the underlying system; the risk is limited to user deception and social engineering outcomes (Chrome Releases, Feedly).
Users and organizations should update Google Chrome on Android to version 144.0.7559.59 or later, which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge Chromium users should apply the patch released on January 16, 2026 (Microsoft MSRC). Enabling automatic updates in Chrome is the most effective way to ensure timely patching. No configuration-based workaround is available; updating to the patched version is the only remediation.
The Chrome 144 release received coverage from security news outlets including Forbes, GBHackers, and CyberSecurityNews, primarily focusing on the broader set of 10 security fixes in the release rather than CVE-2026-0906 specifically. The vulnerability was noted as Low severity by Google, and community discussion was limited given the absence of active exploitation or a public PoC. The CIS published an advisory noting that multiple vulnerabilities in Chrome 144 could allow for arbitrary code execution (referring to the higher-severity issues in the same release), which may have contributed to some confusion about the severity of CVE-2026-0906 (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."