UI Spoofing Vulnerability in Google Chrome by Google
CVE-2025-8583

4.3MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
7 August 2025

What is CVE-2025-8583?

A vulnerability in Google Chrome's permissions implementation prior to version 139.0.7258.66 allows remote attackers to conduct UI spoofing via specially crafted HTML pages. This can mislead users into providing sensitive information without their knowledge.

Affected Version(s)

Chrome 139.0.7258.66

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8583 : UI Spoofing Vulnerability in Google Chrome by Google