UI Spoofing Vulnerability in Google Chrome Affects User Interaction
CVE-2025-8577
4.3MEDIUM
What is CVE-2025-8577?
A vulnerability in the Picture In Picture feature of Google Chrome prior to version 139.0.7258.66 allows remote attackers to manipulate the user interface by persuading them to perform specific gestures. This can be achieved through a specially crafted HTML page, potentially leading to UI spoofing. The impact of this vulnerability could result in users being misled in their interactions, posing significant risks for data security and privacy.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Chrome 139.0.7258.66
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved