Upvote 1

Address Bar Spoofing Vulnerability in Aloha Browser (Android) via Fullscreen API

Known Fanda Dwi Aprilianto ● 19 hours ago

Summary


An Address Bar Spoofing vulnerability was identified in Aloha Browser

for Android. When a website enters fullscreen mode, the real address

bar is completely hidden and Aloha Browser does not display any

persistent fullscreen notification or trusted indicator. An attacker

can render a fake address bar displaying a trusted domain (e.g.,

google.com) while actually rendering content from a malicious origin.


This vulnerability is consistent with the security concern that the

Chromium team has publicly acknowledged in the Chrome Fullscreen

Security FAQ:


"It's difficult for users to figure out whether they are in fullscreen

mode or not because the website can control all pixels on the screen."


Reference:

https://chromium.googlesource.com/chromium/src/+/main/docs/security/fullscreen.md


Aloha Browser uses Chromium as its engine but does not implement the

fullscreen security mitigations that the Chromium team has already

prioritized (persistent fullscreen notification, trusted browser UI in

sensitive security scenarios).


Environment


• Application: Aloha Browser

• Version: 8.11.1

• Platform: Android

• Engine: Chromium

• Device Tester: Samsung A05

• Date of Discovery: 06 October 2026


Steps to Reproduce


Option A: Using a Local Server via Termux (LAN/Wi-Fi Network)


1. Open Termux on the Android device, create a new working directory, and navigate into it:


mkdir poc-aloha && cd poc-aloha


2. Create an index.html file and paste the HTML PoC code into it:


nano index.html


3. Start a local HTTP server using Python:


python -m http.server 8000


4. Open Aloha Browser on the target Android device.

5. Access the PoC page via your local IP/Wi-Fi address:


http://192.168.1.4:8000/index.html


(Adjust 192.168.1.4 to match your local LAN/Wi-Fi IP address.)


Option B: Using Public Hosting (Alternative to Localhost)


1. Deploy the index.html PoC file to a free public hosting service (such as Vercel, Netlify, or GitHub Pages).

2. Open Aloha Browser and navigate to the public URL (e.g., https://poc-spoof.vercel.app/index.html).


Expected Result


The browser's address bar should consistently and accurately display

the actual origin (scheme + host) of the loaded content to ensure user

security. When entering fullscreen mode, the browser should display a

persistent, trusted notification indicating that the user is in

fullscreen mode, along with the true origin.


Actual Result


When entering fullscreen mode, the address bar is completely hidden and

no fullscreen notification is displayed. An attacker can render a fake

address bar displaying "http://www.google.com" along with a VPN shield icon,

despite the page content being served from a different origin. This

misleads the user into believing they are on a legitimate site.


Impact


This vulnerability allows for convincing phishing attacks. Users may

be tricked into providing sensitive information, such as login

credentials or financial data, because the UI provides a false sense

of security by showing a trusted URL and a VPN shield indicator.


Attack scenarios include:


• Credential Phishing — fake Google login page, fake banking page,

fake social media login

• Malware Distribution — fake software update page, fake app download

page

• Social Engineering — fake customer support page, fake payment page


The address bar is the primary indicator of a site's authenticity.

Spoofing it enables phishing attacks that are difficult for users to

detect.


Vulnerability Classification


• Vulnerability Type: Address Bar Spoofing / UI Misrepresentation

• CWE-451 (User Interface (UI) Misrepresentation of Critical Information)

• CWE-1021 (Improper Restriction of Rendered UI Layers or Frames)

• CWE-284 (Improper Access Control)

• OWASP Top 10 A01:2021 — Broken Access Control


Proof of Concept (PoC)


Attached PoC HTML file (index.html) demonstrates the vulnerability.


The PoC:

1. Triggers the Fullscreen API on button tap.

2. Hides the real address bar.

3. Renders a fake address bar displaying "http://www.google.com" along with

a VPN shield icon.

4. Renders a fake Google login page.

5. Captures entered credentials and displays a confirmation overlay

("This Is Not Google").


Video demonstration and screenshots are attached.


Remediation Suggestions


• Origin Validation: Implement stricter URL parsing to ensure the UI

component for the address bar always reflects the true origin after

all redirects and fullscreen transitions.


• Fullscreen Notification: Display a persistent, trusted fullscreen

notification that cannot be obscured by web content, including the

true origin.


• Trusted Browser UI: Ensure trusted browser UI is shown in sensitive

security scenarios and prevent custom UI from overlaying the address

bar area.


• Follow Chromium's Fullscreen Security Model:

https://chromium.googlesource.com/chromium/src/+/main/docs/security/fullscreen.md


References


1. Chromium Fullscreen Security FAQ

https://chromium.googlesource.com/chromium/src/+/main/docs/security/fullscreen.md


2. CVE-2020-7364 — UC Browser Address Bar Spoofing

https://nvd.nist.gov/vuln/detail/CVE-2020-7364


3. CVE-2020-7363 — UC Browser UI Misrepresentation

https://nvd.nist.gov/vuln/detail/CVE-2020-7363


4. CVE-2022-2611 — Chrome Android Fullscreen Spoof

https://nvd.nist.gov/vuln/detail/CVE-2022-2611


5. CVE-2026-84330 — Chrome Android UI Misrepresentation in Fullscreen

https://nvd.nist.gov/vuln/detail/CVE-2026-84330


6. CWE-451 — User Interface (UI) Misrepresentation of Critical Information

https://cwe.mitre.org/data/definitions/451.html


7. CWE-1021 — Improper Restriction of Rendered UI Layers or Frames

https://cwe.mitre.org/data/definitions/1021.html


8. OWASP Top 10 A01:2021 — Broken Access Control

https://owasp.org/Top10/A01_2021-Broken_Access_Control/


Ethical Statement


I am submitting this report in good faith and declare that:


• Verification was performed in a limited manner solely to confirm

the vulnerability.

• I did not attempt to exploit the vulnerability beyond verification

(no real credential theft, no unauthorized access, no data

modification).

• This report is made solely to help improve security and protect

Aloha Browser users.

• I will not publicly disclose this issue before it is fixed.

• I will give Aloha Browser reasonable time to fix it.


Contact


Name: Fanda Dwi Aprilianto

Email: fandadwi72@gmail.com

Leave a Comment
 
Attach a file
Access denied