CVE-2025-0996 describes an inappropriate implementation in the Browser UI of Google Chrome on Android, affecting versions prior to 133.0.6943.98. This high-severity vulnerability allows a remote attacker to spoof the Omnibox (URL bar) content through a specially crafted HTML page. The attack requires user interaction (UI:R) but has low impact on confidentiality and integrity (C:L/I:L), with a CVSS score of 5.4 (Medium). There is currently no evidence of active exploitation, and public exploit code is unavailable, though it has garnered some community discussion and media coverage, including a bug bounty payout.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 133.0.6943.98CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 133.0.6943.98, < 133.0.6943.98CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.