CVE-2025-3072 describes an inappropriate implementation in Google Chrome's Custom Tabs feature, affecting versions prior to 135.0.7049.52. This vulnerability allows a remote attacker to perform UI spoofing through a crafted HTML page if a user is convinced to engage in specific UI gestures. Rated with a CVSS score of 5.4 (MEDIUM), the attack requires user interaction and could lead to low impact on confidentiality and integrity. There is currently no evidence of active exploitation, no public exploit code available, and it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 135.0.7049.52CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 135.0.7049.52, < 135.0.7049.52CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.