Browser UI Spoofing Vulnerability in Google Chrome for Android
CVE-2025-0996

5.4MEDIUM

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
15 February 2025

Summary

A vulnerability in the implementation of the Browser UI in Google Chrome for Android allows a malicious actor to spoof the Omnibox content through a specially crafted HTML page. This exploit could mislead users by displaying deceptive URLs, potentially facilitating phishing attacks. Users of Google Chrome on Android versions prior to 133.0.6943.98 are at risk and should consider updating to maintain security.

Affected Version(s)

Chrome 133.0.6943.98

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.