PT-2025-29147 · Openai · Openai Operator Saas

Shhnjk

·

Published

2025-07-10

·

Updated

2025-07-11

·

CVE-2025-7021

CVSS v4.0

6.9

Medium

VectorAV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: OpenAI Operator SaaS on Web (affected versions not specified)
Description: A flaw exists in the handling of the Fullscreen API and UI rendering that allows a remote attacker to capture sensitive user input, such as login credentials and email addresses. This is achieved by displaying a deceptive fullscreen interface with fake browser controls and a distracting element, like a cookie consent screen, to obscure fullscreen notifications. This manipulation tricks users into interacting with a malicious site.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2025-7021

Affected Products

Openai Operator Saas