UI Spoofing Vulnerability in Google Chrome Affects User Interaction
CVE-2025-8577

4.3MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-8577?

A vulnerability in the Picture In Picture feature of Google Chrome prior to version 139.0.7258.66 allows remote attackers to manipulate the user interface by persuading them to perform specific gestures. This can be achieved through a specially crafted HTML page, potentially leading to UI spoofing. The impact of this vulnerability could result in users being misled in their interactions, posing significant risks for data security and privacy.

Affected Version(s)

Chrome 139.0.7258.66

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8577 : UI Spoofing Vulnerability in Google Chrome Affects User Interaction