UI Spoofing Vulnerability in Google Chrome on Windows
CVE-2025-12434

4.2MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
10 November 2025

What is CVE-2025-12434?

A race condition in the storage handling of Google Chrome on Windows prior to version 142.0.7444.59 enables remote attackers to perform UI spoofing attacks. By enticing users to engage in specific user interface gestures on a maliciously crafted HTML page, attackers can create misleading or deceptive visual effects, which can lead to unauthorized access or actions by the user. This vulnerability underscores the importance of browser security and vigilance in web interactions.

Affected Version(s)

Chrome 142.0.7444.59

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12434 : UI Spoofing Vulnerability in Google Chrome on Windows