Google Chrome before 45.0.2454.85 does not display a location bar for a hosted app's window after navigation away from the installation site, which might make it easier for remote attackers to spoof content via a crafted app, related to browser.cc and hosted_app_browser_controller.cc.
https://codereview.chromium.org/1164873003/
https://code.google.com/p/chromium/issues/detail?id=526825
https://code.google.com/p/chromium/issues/detail?id=467844
http://www.securitytracker.com/id/1033472
http://googlechromereleases.blogspot.com/2015/09/stable-channel-update.html