CVE-2025-3072

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 2, 2025
Updated: Apr 21, 2025

Summary

CVE-2025-3072 is a low-severity vulnerability affecting Google Chrome's Custom Tabs feature before version 135.0.7049.52. An attacker could exploit this issue by convincing a user to perform specific UI gestures on a maliciously crafted HTML page. The vulnerability stems from an inappropriate implementation in Custom Tabs that allows for UI spoofing. This security flaw poses a potential risk to user privacy and security, but requires user interaction to be triggered. Users are advised to update their Google Chrome browsers to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • MySQL Client
  • Oracle Mysql Cluster

Affected Vendors

  • Oracle