New phishing exploit discovered in Google Chrome for Android


  • TECH
  • Tuesday, 30 Apr 2019

Google Play

Developer James Fisher has discovered an exploit in Google Chrome for Android that can be used for phishing attacks.

The exploit, dubbed “inception bar” by Fisher, takes advantage of the fact that the browser hides the address bar when a users scrolls down a page – when that happens the exploit displays a fake address bar, making the phishing site look like a legitimate one.

When the user scrolls up again, the exploit can force Chrome into keeping the real address bar hidden so the user will not know any better.

This attack can be used to trick users into thinking that they are on, say, a legitimate banking website so they will enter their username and password.

The method Fisher demonstrated uses a screenshot of an address bar of a bank – it looks convincing but if a user tries interacting with it the person would discover that it’s just an image.

While this exploit also works on Apple devices, it won’t fool anyone as the iOS version of Chrome doesn’t hide the address bar when a user scrolls down so they will see both the fake and real address bars.

Limited time offer:
Just RM5 per month.

Monthly Plan

RM13.90/month
RM5/month

Billed as RM5/month for the 1st 6 months then RM13.90 thereafters.

Annual Plan

RM12.33/month

Billed as RM148.00/year

1 month

Free Trial

For new subscribers only


Cancel anytime. No ads. Auto-renewal. Unlimited access to the web and app. Personalised features. Members rewards.
Follow us on our official WhatsApp channel for breaking news alerts and key updates!
   

Next In Tech News

Amazon Prime Video to exclusively stream two NHL seasons in Canada
T-Mobile to invest $950 million in venture with EQT to buy fiber optic network provider Lumos
Hertz Global eyes worst day on record as EV rental business falters
EU court adviser backs data privacy activist Schrems in Meta fight
Spotify says Apple has rejected its app update with price information for EU users
Amazon to invest $11 billion in Indiana to build data centers
IBM falls as enterprise-spending constraints choke consulting demand
Net neutrality rules to be restored in US agency vote
India's Tech Mahindra misses Q4 revenue view on weak communications segment
Explainer-Where are Wall Street's analyst notes on Trump's Truth Social?

Others Also Read