CVE-2026-3925
vulnerability analysis and mitigation

Overview

CVE-2026-3925 is an incorrect security UI vulnerability in the LookalikeChecks component of Google Chrome on Android, allowing a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by NDevTK and Alesandro Ortiz on 2025-05-17 and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects Google Chrome on Android versions prior to 146.0.7680.71, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, Feedly).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), specifically within Chrome's LookalikeChecks subsystem on Android, which is responsible for detecting and warning users about lookalike/typosquatting domains. An attacker can craft a malicious HTML page that, when visited by a user on an affected Android Chrome browser, causes the browser to incorrectly render or suppress security UI elements — such as lookalike domain warnings — thereby deceiving the user about the authenticity of the site. Exploitation requires no privileges and no special configuration, but does require user interaction (visiting the attacker-controlled page). The Chromium bug tracker issue is referenced as #418214610 (Chrome Releases, Feedly).

Impact

Successful exploitation primarily affects integrity, as the attacker can manipulate the browser's security UI to suppress or spoof lookalike domain warnings on Android devices, potentially deceiving users into believing they are visiting a legitimate website. This creates a significant risk of phishing attacks, credential theft, and other social engineering scenarios that rely on users trusting browser security indicators. Confidentiality and availability are not directly impacted by this vulnerability, and there is no known path to code execution or lateral movement (Feedly).

Exploitation steps

  1. Reconnaissance: Identify Android users running Google Chrome versions prior to 146.0.7680.71, which can be inferred from user-agent strings in web server logs or targeted phishing campaigns.
  2. Craft malicious HTML page: Develop a crafted HTML page that exploits the incorrect handling of LookalikeChecks in Chrome for Android, causing the browser to suppress or misrepresent the lookalike domain security warning UI.
  3. Deliver the page: Lure the target user to visit the malicious page via phishing email, SMS, or social media link — user interaction is required for exploitation.
  4. UI spoofing achieved: When the victim visits the page on a vulnerable Android Chrome browser, the expected security warning (e.g., lookalike domain alert) is not displayed or is spoofed, causing the user to believe the site is legitimate.
  5. Harvest credentials or data: With the security warning suppressed, the attacker can present a convincing phishing page to steal credentials, session tokens, or other sensitive information (Chrome Releases, Feedly).

Indicators of compromise

  • Network: HTTP/HTTPS requests from Android Chrome user-agents (versions < 146.0.7680.71) to suspicious lookalike domains that closely resemble legitimate sites (e.g., paypa1.com, g00gle.com).
  • Logs: Web server access logs showing Android Chrome clients visiting pages with crafted HTML designed to trigger or suppress LookalikeChecks UI; absence of expected browser-side warning interactions.
  • User Reports: End-user reports of visiting a site that appeared legitimate but did not display the expected Chrome security warning for a suspicious domain.

Mitigation and workarounds

Update Google Chrome on all Android devices to version 146.0.7680.71 or later, which was released on March 10, 2026 and contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding update via the Microsoft Security Response Center advisory. Enable automatic updates in Chrome to ensure timely receipt of future security patches. As a general precaution, educate users to verify domain names carefully and avoid clicking links from untrusted sources, particularly on mobile devices where URL bars may display less information.

Community reactions

The vulnerability was covered by GBHackers in an article noting that the Chrome 146 update addressed 29 vulnerabilities, including CVE-2026-3925 (GBHackers). Security aggregators such as VulDB, Tenable (Nessus), and Qualys have published detection plugins for the vulnerability. Linux distribution security teams (Debian, Fedora, openSUSE) issued advisories for their Chromium packages. No significant independent researcher commentary or social media discussion specific to this CVE has been identified beyond standard vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management