UI Spoofing Vulnerability in Google Chrome Affecting Multiple Versions
CVE-2025-8579
4.3MEDIUM
What is CVE-2025-8579?
A vulnerability in Google Chrome allows for UI spoofing through inappropriate implementation in the Picture In Picture feature. This issue can enable a remote attacker to manipulate the user interface by tricking users into engaging in specific UI gestures while visiting a maliciously crafted HTML page, potentially leading to unauthorized actions or exposure of sensitive information.
Affected Version(s)
Chrome 139.0.7258.66