CVE-2025-0435 describes an inappropriate implementation vulnerability in Google Chrome on Android, specifically versions prior to 132.0.6834.83, which allows a remote attacker to perform UI spoofing through a crafted HTML page. This high-severity vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited over a network with low attack complexity, requiring user interaction to achieve a high impact on integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 132.0.6834.83CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 132.0.6834.83, < 132.0.6834.83CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.