Summary by Moch_Azril
A UI-confusion vulnerability allows a webpage to trigger a browser fullscreen request and immediately redirect to an external application using a tel: URI. The resulting system-level external-application prompt can overlap or obscure the browser's fullscreen notification.
This creates a trusted-UI spoofing condition where users may be unable to clearly distinguish which action they are authorizing. When combined with attacker-controlled fullscreen content or another security-sensitive browser prompt such as WebAuthn, the issue could facilitate clickjacking, permission spoofing, and phishing attacks.