UI Spoofing Vulnerability in Google Chrome by Google
CVE-2025-8580

4.3MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-8580?

An implementation flaw in the Filesystems component of Google Chrome versions prior to 139.0.7258.66 enables remote attackers to execute UI spoofing attacks. By crafting a malicious HTML page, attackers can manipulate the user interface, deceiving users into interacting with what appears to be legitimate content. This raises significant security concerns, particularly in environments where sensitive transactions occur.

Affected Version(s)

Chrome 139.0.7258.66

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8580 : UI Spoofing Vulnerability in Google Chrome by Google