UI Spoofing Vulnerability in Google Chrome
CVE-2025-1923

4.3MEDIUM

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
5 March 2025

Summary

An improper implementation in permission prompts within Google Chrome versions prior to 134.0.6998.35 enables attackers to exploit users by convincing them to install malicious extensions. This flaw allows for UI spoofing attacks, where an attacker can craft deceptive interfaces that mislead users into providing sensitive information or performing unintended actions. Users must ensure their browsers are updated to mitigate potential exploitation of this vulnerability.

Affected Version(s)

Chrome 134.0.6998.35

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.