CVE-2025-9865 describes a medium-severity domain spoofing vulnerability in Google Chrome on Android, specifically versions prior to 140.0.7339.80. This flaw, categorized as an "inappropriate implementation" (CWE-451), allows a remote attacker to mislead users about the website they are visiting through a crafted HTML page, requiring specific user interaction. The CVSS score of 5.4 indicates a network-based attack with low complexity but requiring user interaction, potentially leading to limited confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 140.0.7339.80, < 140.0.7339.80CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 140.0.7339.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.