Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
https://security.gentoo.org/glsa/202208-25
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15854
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html