PT-2025-46937 · Google+2 · Google Chrome+2

Published

2025-07-03

·

Updated

2025-12-02

·

CVE-2025-13107

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 140.0.7339.80
Description An issue in Compositing within Google Chrome, prior to version 140.0.7339.80, could allow a remote attacker to perform UI spoofing through a specially designed HTML page. This is due to an inappropriate implementation in the Compositing component.
Recommendations Update Google Chrome to version 140.0.7339.80 or later.

Exploit

Fix

UI Misrepresentation of Critical Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14878
CVE-2025-13107
DSA-5993-1

Affected Products

Debian
Google Chrome
Red Os