UI Spoofing Vulnerability in Google Chrome for Android
CVE-2025-9867

5.4MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
3 September 2025

What is CVE-2025-9867?

A vulnerability in Google Chrome for Android allows remote attackers to exploit inappropriate implementation in the Downloads feature. By leveraging a specially crafted HTML page, an attacker can perform UI spoofing, potentially misleading users into providing sensitive information under the guise of legitimate interfaces.

Affected Version(s)

Chrome 140.0.7339.80

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9867 : UI Spoofing Vulnerability in Google Chrome for Android