CVE-2025-11210
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.4epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in Google Chrome's Tab feature allows attackers to trick users through visual deception by manipulating browser UI elements when users interact with the page in specific ways. This could fool users into clicking on fake buttons or believing they're on a different website.
Technical detail
CWE-1300 side-channel information leakage in Chrome's Tab component (prior to 141.0.7390.54) permits UI spoofing attacks via crafted HTML pages when users perform specific gestures. The vulnerability requires user interaction and convincing social engineering, but enables attackers to deceive users about the true origin or content of displayed UI elements.
Summary generated and translated by AI from the official description.
Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected products
Google · Chrome