CVE-2025-11210 is a medium-severity side-channel information leakage vulnerability in Google Chrome versions prior to 141.0.7390.54, affecting Apple, Google, Linux, and Microsoft platforms. An unauthenticated remote attacker could exploit this by convincing a user to perform specific UI gestures on a crafted HTML page, leading to UI spoofing and potential information disclosure (CVSS 5.4). While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 141.0.7390.54CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 141.0.7390.54, < 141.0.7390.54CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.