There’s a new Chrome attack on the horizon, and man, it’s a doozy. Dubbed the “Inception Bar” by the finder , it replicates Chrome’s Omnibox, essentially giving attackers the potential to take control of Chrome completely. Found by developer James Fisher, the Inception Bar is an incredibly clever phishing attack that leverages the fact that Chrome for Android hides the Omnibox—that’s what the address bar on Chrome is called—as you scroll. Once you scroll down the page a bit, the Omnibox is hidden, and it’s automatically replaced with the spoofed bar. And it looks incredibly convincing —it can even lock the real Omnibox in an overflow container, preventing it from re-appearing once the Inception Bar is in place. While it doesn’t look like this attack has been found present on the web (yet), Fisher built a working proof of concept on his site , which you can check out at the link. Once you visit the site, scroll down the page a bit, and right after the Omnibox disappears, yo...