PT-2025-1281 · Google+2 · Google Chrome+2

Umar Farooq

·

Published

2025-01-14

·

Updated

2025-07-02

·

CVE-2025-0440

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 132.0.6834.83
Description The issue is related to an inappropriate implementation in Fullscreen mode, allowing a remote attacker to perform UI spoofing via a crafted HTML page. This could enable the attacker to bypass existing security restrictions and execute a user interface spoofing attack. The severity of this issue is classified as medium by Chromium.
Recommendations For Google Chrome versions prior to 132.0.6834.83, update to version 132.0.6834.83 or later to resolve the issue. As a temporary workaround, consider disabling Fullscreen mode until a patch is available. Restrict access to crafted HTML pages to minimize the risk of exploitation. Avoid using Fullscreen mode in Google Chrome on Windows until the issue is resolved.

Exploit

Fix

LPE

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1607
ALT-PU-2025-3969
ALT-PU-2025-4366
ALT-PU-2025-7539
ALT-PU-2025-8547
BDU:2025-00749
CVE-2025-0440
DSA-5844-1
OPENSUSE-SU-2025:0018-1
OPENSUSE-SU-2025:14659-1

Affected Products

Alt Linux
Debian
Google Chrome