Address Bar Spoofing Vulnerability in Aloha Browser (Android) via Fullscreen API
Summary
An Address Bar Spoofing vulnerability was identified in Aloha Browser
for Android. When a website enters fullscreen mode, the real address
bar is completely hidden and Aloha Browser does not display any
persistent fullscreen notification or trusted indicator. An attacker
can render a fake address bar displaying a trusted domain (e.g.,
google.com) while actually rendering content from a malicious origin.
This vulnerability is consistent with the security concern that the
Chromium team has publicly acknowledged in the Chrome Fullscreen
Security FAQ:
"It's difficult for users to figure out whether they are in fullscreen
mode or not because the website can control all pixels on the screen."
Reference:
https://chromium.googlesource.com/chromium/src/+/main/docs/security/fullscreen.md
Aloha Browser uses Chromium as its engine but does not implement the
fullscreen security mitigations that the Chromium team has already
prioritized (persistent fullscreen notification, trusted browser UI in
sensitive security scenarios).
Environment
• Application: Aloha Browser
• Version: 8.11.1
• Platform: Android
• Engine: Chromium
• Device Tester: Samsung A05
• Date of Discovery: 06 October 2026
Steps to Reproduce
Option A: Using a Local Server via Termux (LAN/Wi-Fi Network)
1. Open Termux on the Android device, create a new working directory, and navigate into it:
mkdir poc-aloha && cd poc-aloha
2. Create an index.html file and paste the HTML PoC code into it:
nano index.html
3. Start a local HTTP server using Python:
python -m http.server 8000
4. Open Aloha Browser on the target Android device.
5. Access the PoC page via your local IP/Wi-Fi address:
http://192.168.1.4:8000/index.html
(Adjust 192.168.1.4 to match your local LAN/Wi-Fi IP address.)
Option B: Using Public Hosting (Alternative to Localhost)
1. Deploy the index.html PoC file to a free public hosting service (such as Vercel, Netlify, or GitHub Pages).
2. Open Aloha Browser and navigate to the public URL (e.g., https://poc-spoof.vercel.app/index.html).
Expected Result
The browser's address bar should consistently and accurately display
the actual origin (scheme + host) of the loaded content to ensure user
security. When entering fullscreen mode, the browser should display a
persistent, trusted notification indicating that the user is in
fullscreen mode, along with the true origin.
Actual Result
When entering fullscreen mode, the address bar is completely hidden and
no fullscreen notification is displayed. An attacker can render a fake
address bar displaying "http://www.google.com" along with a VPN shield icon,
despite the page content being served from a different origin. This
misleads the user into believing they are on a legitimate site.
Impact
This vulnerability allows for convincing phishing attacks. Users may
be tricked into providing sensitive information, such as login
credentials or financial data, because the UI provides a false sense
of security by showing a trusted URL and a VPN shield indicator.
Attack scenarios include:
• Credential Phishing — fake Google login page, fake banking page,
fake social media login
• Malware Distribution — fake software update page, fake app download
page
• Social Engineering — fake customer support page, fake payment page
The address bar is the primary indicator of a site's authenticity.
Spoofing it enables phishing attacks that are difficult for users to
detect.
Vulnerability Classification
• Vulnerability Type: Address Bar Spoofing / UI Misrepresentation
• CWE-451 (User Interface (UI) Misrepresentation of Critical Information)
• CWE-1021 (Improper Restriction of Rendered UI Layers or Frames)
• CWE-284 (Improper Access Control)
• OWASP Top 10 A01:2021 — Broken Access Control
Proof of Concept (PoC)
Attached PoC HTML file (index.html) demonstrates the vulnerability.
The PoC:
1. Triggers the Fullscreen API on button tap.
2. Hides the real address bar.
3. Renders a fake address bar displaying "http://www.google.com" along with
a VPN shield icon.
4. Renders a fake Google login page.
5. Captures entered credentials and displays a confirmation overlay
("This Is Not Google").
Video demonstration and screenshots are attached.
Remediation Suggestions
• Origin Validation: Implement stricter URL parsing to ensure the UI
component for the address bar always reflects the true origin after
all redirects and fullscreen transitions.
• Fullscreen Notification: Display a persistent, trusted fullscreen
notification that cannot be obscured by web content, including the
true origin.
• Trusted Browser UI: Ensure trusted browser UI is shown in sensitive
security scenarios and prevent custom UI from overlaying the address
bar area.
• Follow Chromium's Fullscreen Security Model:
https://chromium.googlesource.com/chromium/src/+/main/docs/security/fullscreen.md
References
1. Chromium Fullscreen Security FAQ
https://chromium.googlesource.com/chromium/src/+/main/docs/security/fullscreen.md
2. CVE-2020-7364 — UC Browser Address Bar Spoofing
https://nvd.nist.gov/vuln/detail/CVE-2020-7364
3. CVE-2020-7363 — UC Browser UI Misrepresentation
https://nvd.nist.gov/vuln/detail/CVE-2020-7363
4. CVE-2022-2611 — Chrome Android Fullscreen Spoof
https://nvd.nist.gov/vuln/detail/CVE-2022-2611
5. CVE-2026-84330 — Chrome Android UI Misrepresentation in Fullscreen
https://nvd.nist.gov/vuln/detail/CVE-2026-84330
6. CWE-451 — User Interface (UI) Misrepresentation of Critical Information
https://cwe.mitre.org/data/definitions/451.html
7. CWE-1021 — Improper Restriction of Rendered UI Layers or Frames
https://cwe.mitre.org/data/definitions/1021.html
8. OWASP Top 10 A01:2021 — Broken Access Control
https://owasp.org/Top10/A01_2021-Broken_Access_Control/
Ethical Statement
I am submitting this report in good faith and declare that:
• Verification was performed in a limited manner solely to confirm
the vulnerability.
• I did not attempt to exploit the vulnerability beyond verification
(no real credential theft, no unauthorized access, no data
modification).
• This report is made solely to help improve security and protect
Aloha Browser users.
• I will not publicly disclose this issue before it is fixed.
• I will give Aloha Browser reasonable time to fix it.
Contact
Name: Fanda Dwi Aprilianto
Email: fandadwi72@gmail.com
Replies have been locked on this page!