Warning About Chrome Flaw In Address Bar

A security researcher has warned of a potential flaw with Chrome for mobile, that could mean users land on bogus websites without realising it.

According to developer James Fisher, he was able to do some clever coding to open up a simple exploit in Chrome for mobile, to make it appear that a user had landed on the banking website HSBC.com, when in actual fact the webpage was hosted on jameshfisher.com.

Chrome of course is Google’s main web browser, and is one of the most popular browsers on the market. Last year Chrome began blocking adverts that were deemed to be annoying or otherwise detrimental to users.

Address bar

But the mobile version has a flaw, according to Fisher. The so called “inception bar attack” exploits the fact that Chrome on mobile hides the address bar when scrolling.

This is a useful feature when scrolling on a smaller screen, as the user can see more more content in the limited space provided.

But this “inception bar attack” takes advantage of that feature.

“In Chrome for mobile, when the user scrolls down, the browser hides the URL bar, and hands the URL bar’s screen space to the web page,” wrote Fisher. “Because the user associates this screen space with ‘trustworthy browser UI’, a phishing site can then use it to pose as a different site, by displaying its own fake URL bar – the inception bar!”

“This is bad, but it gets worse,” he added. “Normally, when the user scrolls up, Chrome will re-display the true URL bar. But we can trick Chrome so that it never re-displays the true URL bar! Once Chrome hides the URL bar, we move the entire page content into a ‘scroll jail’ – that is, a new element with overflow:scroll. Then the user thinks they’re scrolling up in the page, but in fact they’re only scrolling up in the scroll jail! Like a dream in Inception, the user believes they’re in their own browser, but they’re actually in a browser within their browser.

Fisher posted a video of the hack in operation here.

There is though a way to double check that you are actually on the correct website.

The 9to5Google team noted that users can force the real address bar to show by locking and then unlocking their phone again.

“This should force Chrome for Android to show its real address bar and leave the fake, exploited one on display too,” they wrote.

Do you know all about security? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

TSMC Denies Talks With Intel Over Chipmaking Joint Venture

Denial from TSMC, after multiple reports it was in talks with Intel over a joint…

3 days ago

Apple iPhone Shipments In China Slide, As Cook Talks With Trump Official

CEO Tim Cook talks to Trump official, as IDC notes China's smartphone market growth, and…

3 days ago

AMD Warns Of $800m Charge From US Chip Restrictions On China

Another big name chip maker expects a hefty financial charge, after the US tightened rules…

3 days ago

Google Digital Ad Network Ruled Illegal Monopoly By Judge

More bad news for Google. Second time in less than a year that some part…

3 days ago

US State Dept Closes Office Flagging Russia, China Disinformation

Federal office that tackled misinformation and disinformation from hostile nations is closed down, after criticism…

3 days ago

Nvidia CEO Jensen Huang Makes Surprise Visit To China

After Nvidia admits it will take $5.5 billion charge as Trump export limits of slower…

3 days ago