CVE-2025-0446
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 15, 2025
CWE ID 290
Summary
CVE-2025-0446 is a low-severity vulnerability affecting Google Chrome versions prior to 132.0.6834.83. This issue stems from an inappropriate implementation in Chrome Extensions, which enables a remote attacker to execute UI spoofing. The attacker can manipulate the user interface by persuading the user to perform specific gestures, leading to potential deception and data theft. It is recommended that users update their Chrome browsers to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.