Insufficient Input Validation in Google Chrome's Omnibox
CVE-2025-8582

4.3MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-8582?

A security vulnerability in Google Chrome prior to version 139.0.7258.66 arises from insufficient validation of untrusted input within the browser's Core component. This flaw permits a remote attacker to manipulate the display content in the Omnibox, leading to potential URL spoofing through maliciously crafted HTML pages. Users are encouraged to update their browser to fortify against this security risk.

Affected Version(s)

Chrome 139.0.7258.66

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8582 : Insufficient Input Validation in Google Chrome's Omnibox