New serious vulnerability in Android browsers leads to phishing attacks
Quite often, users identify a malicious website by the URL in the address bar. A new vulnerability allows attackers to spoof the URL in Android's Stock browser, which can trick users into providing sensitive personal information to phishing websites.
vulnerability issue for Android Lollipop as well as earlier versions. The problem arises because Android browsers fail to handle the 204 “No Content” error that occurs when combined with a window.open event, thus allowing hackers to spoof the address bar.
In a proof of the so-called it appears that, in the event that the site is without content, and is opened with the unpatched Android Stock browser, users are redirected to a page with the URL “https://www.google.com/csi”.
This leads the user to think that it is a secure site hosted on Google when in fact it is a phishing site. Once users enter their credentials, they will automatically be sent to attacker.com.
The issue was reported to the Android security team by Rafah Baloch in February. The security has released patches for both Kitkat and Lollipop. Users are advised to contact their security providers to make sure they have received the updates.

