UI Spoofing Vulnerability in Google Chrome for Android
CVE-2025-12435

5.4MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
10 November 2025

What is CVE-2025-12435?

A vulnerability in Google Chrome for Android has been identified, where an incorrect security user interface in the Omnibox allows remote attackers to perform UI spoofing. By utilizing a specially crafted HTML page, malicious actors can deceive users into interacting with a fraudulent interface, compromising user trust and potentially leading to unauthorized actions. This issue affects versions of Google Chrome on Android prior to 142.0.7444.59.

Affected Version(s)

Chrome 142.0.7444.59

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12435 : UI Spoofing Vulnerability in Google Chrome for Android