
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3925 is an incorrect security UI vulnerability in the LookalikeChecks component of Google Chrome on Android, allowing a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by NDevTK and Alesandro Ortiz on 2025-05-17 and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects Google Chrome on Android versions prior to 146.0.7680.71, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, Feedly).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), specifically within Chrome's LookalikeChecks subsystem on Android, which is responsible for detecting and warning users about lookalike/typosquatting domains. An attacker can craft a malicious HTML page that, when visited by a user on an affected Android Chrome browser, causes the browser to incorrectly render or suppress security UI elements — such as lookalike domain warnings — thereby deceiving the user about the authenticity of the site. Exploitation requires no privileges and no special configuration, but does require user interaction (visiting the attacker-controlled page). The Chromium bug tracker issue is referenced as #418214610 (Chrome Releases, Feedly).
Successful exploitation primarily affects integrity, as the attacker can manipulate the browser's security UI to suppress or spoof lookalike domain warnings on Android devices, potentially deceiving users into believing they are visiting a legitimate website. This creates a significant risk of phishing attacks, credential theft, and other social engineering scenarios that rely on users trusting browser security indicators. Confidentiality and availability are not directly impacted by this vulnerability, and there is no known path to code execution or lateral movement (Feedly).
paypa1.com, g00gle.com).Update Google Chrome on all Android devices to version 146.0.7680.71 or later, which was released on March 10, 2026 and contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding update via the Microsoft Security Response Center advisory. Enable automatic updates in Chrome to ensure timely receipt of future security patches. As a general precaution, educate users to verify domain names carefully and avoid clicking links from untrusted sources, particularly on mobile devices where URL bars may display less information.
The vulnerability was covered by GBHackers in an article noting that the Chrome 146 update addressed 29 vulnerabilities, including CVE-2026-3925 (GBHackers). Security aggregators such as VulDB, Tenable (Nessus), and Qualys have published detection plugins for the vulnerability. Linux distribution security teams (Debian, Fedora, openSUSE) issued advisories for their Chromium packages. No significant independent researcher commentary or social media discussion specific to this CVE has been identified beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."