CVE-2025-0435 Details
Description
Inappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
A UI spoofing vulnerability has been identified in Google Chrome on Android, in versions prior to 132.0.6834.83. This issue allows remote attackers to manipulate the user interface by hiding the address bar and spoofing the URL display, using a specially crafted HTML page. The vulnerability arises from an improper handling of navigation events, particularly with the 'RenderDocument' feature, which can disrupt the expected sequence of page load notifications. As a result, the address bar can be concealed without user interaction, creating an opportunity for phishing attacks by misrepresenting the actual website being viewed.
Users can update to Google Chrome version 132.0.6834.83 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_14.html | [email protected] | Vendor Advisory |
| https://issues.chromium.org/issues/379652406 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-451 | User Interface (UI) Misrepresentation of Critical Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google chrome | < 132.0.6834.83 |
CPE
Remediation
| |
| google android | 12.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 21, 2025 | Initial Analysis | [email protected] |
| Mar 19, 2025 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Jan 15, 2025 | CVE Modified | CISA-ADP |
| Jan 15, 2025 | New CVE Received | [email protected] |