Proof of Concept Suite - Critical Unfixed Surfaces
This PoC suite is for authorized security research and testing only. Do not use against real users or systems you don't own. Report findings responsibly to Chromium security team.
CVE Status: Partially fixed (CL 7536052)
Fix Coverage: ~23% (permission prompts only)
Unfixed Surfaces: 27+ UI surfaces remain vulnerable
Severity: CRITICAL (S2) - Credential theft, financial fraud, identity theft
What's the issue?
The Google Sans font contains special ligatures that render strings like "googlelogoligature" as the Google logo. When these strings appear in domain names, Chrome displays them as the logo in various UI surfaces, allowing attackers to spoof Google's origin.
What was fixed?
CL 7536052 disabled ligatures in permission prompts (camera, microphone, location, etc.) on Android.
What remains vulnerable?
The 7 critical surfaces demonstrated in this PoC suite, plus 20+ other surfaces.
googlelogoligature.com to this serverWhat to look for:
[Google Logo].com instead of googlelogoligature.com?After testing, report findings to: