Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2025-11213: Inappropriate implementation in Google Chrome

0
Medium
VulnerabilityCVE-2025-11213cvecve-2025-11213
Published: Thu Nov 06 2025 (11/06/2025, 22:08:56 UTC)
Source: CVE Database V5
Vendor/Project: Google
Product: Chrome

Description

Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)

AI-Powered Analysis

AILast updated: 11/13/2025, 23:57:04 UTC

Technical Analysis

CVE-2025-11213 is a vulnerability identified in the Omnibox component of Google Chrome on Android platforms prior to version 141.0.7390.54. The Omnibox is the combined address and search bar in Chrome, critical for displaying the URL and ensuring users can verify the authenticity of websites they visit. This vulnerability arises from an inappropriate implementation that allows a remote attacker to craft a malicious HTML page which, when a user performs specific UI gestures, can spoof the domain displayed in the Omnibox. This domain spoofing can mislead users into believing they are visiting a legitimate site when they are not, facilitating phishing attacks or other social engineering exploits. The attack vector requires no privileges or prior authentication but does require user interaction, specifically certain UI gestures that trigger the spoofing. The CVSS v3.1 score is 6.3 (medium severity), reflecting the moderate impact on confidentiality, integrity, and availability, combined with the need for user interaction. The vulnerability is classified under CWE-451 (Incorrect Expression of User Interface in Security Decision). No public exploits have been reported yet, and no official patch links are provided in the data, but upgrading to Chrome version 141.0.7390.54 or later is implied as the remediation. This vulnerability highlights the importance of secure UI design in browser components that directly affect user trust and security.

Potential Impact

For European organizations, this vulnerability poses a risk primarily through social engineering and phishing attacks leveraging domain spoofing. Attackers can deceive users into divulging sensitive information, such as credentials or financial data, by presenting fake but convincing URLs in the browser's Omnibox. This can lead to data breaches, financial fraud, and compromise of user accounts. The impact extends to brand reputation damage and potential regulatory penalties under GDPR if personal data is compromised. Organizations with a mobile-first workforce or those relying heavily on Android devices for business operations are particularly vulnerable. The medium severity indicates that while the vulnerability is not trivially exploitable without user interaction, the potential for targeted attacks against high-value users or executives exists. Additionally, the integrity of communications and availability of services could be indirectly affected if users are redirected to malicious sites or malware distribution points.

Mitigation Recommendations

The primary mitigation is to update Google Chrome on all Android devices to version 141.0.7390.54 or later, where the vulnerability is fixed. Organizations should enforce mobile device management (MDM) policies to ensure timely updates and prevent the use of outdated browser versions. User education is critical: train users to recognize suspicious UI behaviors and avoid performing unusual gestures or interactions on untrusted websites. Implement multi-factor authentication (MFA) to reduce the impact of credential theft resulting from phishing. Employ endpoint protection solutions that can detect and block access to known malicious URLs or phishing sites. Additionally, organizations should monitor network traffic for signs of phishing campaigns exploiting this vulnerability and conduct regular security awareness campaigns emphasizing safe browsing practices on mobile devices.

Need more detailed analysis?Get Pro

Technical Details

Data Version
5.2
Assigner Short Name
Chrome
Date Reserved
2025-09-30T21:50:13.738Z
Cvss Version
null
State
PUBLISHED

Threat ID: 690d1f60a155e591f58b659e

Added to database: 11/6/2025, 10:21:20 PM

Last enriched: 11/13/2025, 11:57:04 PM

Last updated: 12/22/2025, 5:36:42 AM

Views: 63

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Related Threats

CVE-2025-11545: CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere in Sharp Display Solutions, Ltd. NP-PA1705UL-W, NP-PA1705UL-W+, NP-PA1705UL-B, NP-PA1705UL-B+, NP-PA1505UL-W, NP-PA1505UL-W+, NP-PA1505UL-B, NP-PA1505UL-B+, NP-PA1505UL-BJL NP-PV800UL-W, NP-PV800UL-W+, NP-PV800UL-B, NP-PV800UL-B+, NP-PV710UL-W, NP-PV710UL-W+, NP-PV710UL-B, NP-PV710UL-B+, NP-PV800UL-W1, NP-PV800UL-B1, NP-PV710UL-W1, NP-PV710UL-B1, NP-PV800UL-B1G, NP-PV710UL-B1G, NP-PV800UL-WH, NP-PV710UL-WH, NP-P627UL, NP-P627ULG, NP-P627UL+, NP-P547UL, NP-P547ULG, NP-P607UL+, NP-CG6600UL, NP-H6271UL, NP-H5471UL, NP-P627ULH, NP-P547ULH NP-PV710UL+ NP-PA1004UL-W, NP-PA1004UL-WG, NP-PA1004UL-W+, NP-PA1004UL-WH, NP-PA1004UL-B, NP-PA1004UL-BG, NP-PA1004UL-B+, NP-PA804UL-W, NP-PA804UL-WG, NP-PA804UL-W+, NP-PA804UL-WH, NP-PA804UL-B, NP-PA804UL-BG, NP-PA804UL-B+, NP-PA1004UL-BH, NP-PA804UL-BH, NP-PE455UL, NP-PE455ULG, NP-PE455WL, NP-PE455WLG, NP-PE505XLG, NP-CG6500XL, NP-CG6400UL, NP-CG6400WL, NP-CB4500XL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, NP-CA4200W, NP-CA4202W, NP-CA4260X, NP-CA4300X, NP-CA4355X, NP-CD2100U, NP-CD2120X, NP-CD2300X, NP-CR2100X, NP-CR2170W, NP-CR2170X, NP-CR2200U, NP-CR2200W, NP-CR2280X, NP-CR2310X, NP-CR2350X, NP-MC302XG, NP-MC332WG, NP-MC342XG, NP-MC372X, NP-MC372XG, NP-MC382W, NP-MC382WG, NP-MC422XG, NP-ME342UG, NP-ME372W, NP-ME372WG, NP-ME382U, NP-ME382UG, NP-ME402X, NP-ME402XG NP-CU4300XD, NP-CU4200XD, NP-CU4200WD, NP-UM383WL, NP-UM383WLG, NP-CJ2200WD, NP-PH3501QL, NP-PH3501QL+, NP-PH2601QL, NP-PH2601QL+, NP-PH350Q40L, NP-PH260Q30L, NP-PX1005QL-W, NP-PX1005QL-B, NP-PX1005QL-B+, NP-P525UL, NP-P525ULG, NP-P525UL+, NP-P525WL, NP-P525WLG, NP-P525WL+, NP-P605UL, NP-P605ULG, NP-P605UL+

Critical
VulnerabilityMon Dec 22 2025

CVE-2025-11544: CWE-912: Hidden Functionality in Sharp Display Solutions, Ltd. NP-P627UL, NP-P627ULG, NP-P627UL+, NP-P547UL, NP-P547ULG, NP-P607UL+, NP-CG6600UL, NP-H6271UL, NP-H5471UL, NP-P627ULH, NP-P547ULH, NP-PE455UL, NP-PE455ULG, NP-PE455WL, NP-PE455WLG, NP-PE505XLG, NP-CG6500XL, NP-CG6400UL, NP-CG6400WL, NP-CB4500XL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, NP-CA4200W, NP-CA4202W, NP-CA4260X, NP-CA4300X, NP-CA4355X, NP-CD2100U, NP-CD2120X, NP-CD2300X, NP-CR2100X, NP-CR2170W, NP-CR2170X, NP-CR2200U, NP-CR2200W, NP-CR2280X, NP-CR2310X, NP-CR2350X, NP-MC302XG, NP-MC332WG, NP-MC342XG, NP-MC372X, NP-MC372XG, NP-MC382W, NP-MC382WG, NP-MC422XG, NP-ME342UG, NP-ME372W, NP-ME372WG, NP-ME382U, NP-ME382UG, NP-ME402X, NP-ME402XG, NP-P525UL, NP-P525ULG, NP-P525UL+, NP-P525WL, NP-P525WLG, NP-P525WL+, NP-P605UL, NP-P605ULG, NP-P605UL+, NP-CG6500UL, NP-CG6500WL, NP-CB4500UL, NP-CB4500WL, NP-P525ULH, NP-P525WLH, NP-P605ULH, NP-P554U, NP-P554UG, NP-P554U+, NP-P554W, NP-P554WG, NP-P554W+, NP-P474U, NP-P474UG, NP-P474W, NP-P474WG, NP-P604XG, NP-P604X+, NP-P603XG, NP-P523X+, NP-PE523XG, NP-PE523X+, NP-CF6600U, NP-CF6600W, NP-CF6700X, NP-CF6500X, NP-CB4600U, NP-P554UH, NP-P554WH, NP-P474UH, NP-P474WH, NP-P604XH, NP-P603XH, NP-PE523XH, NP-P502HL-2, NP-P502WL-2, NP-P502HLG-2, NP-P502WLG ,NP-ME401W, NP-ME361W, NP-ME331W, NP-ME301W, NP-ME401X, NP-ME361X, NP-ME331X, NP-ME301X, NP-ME401WG, NP-ME361WG, NP-ME331WG, NP-ME301WG, NP-ME401XG, NP-ME361XG, NP-ME331XG, NP-ME301XG, NP-CA4155W, NP-CA4350X, NP-CA4255X, NP-CA4155X, NP-CA4115X, NP-MC331WG, NP-MC421XG, NP-MC401XG, NP-MC371XG, NP-MC331XG, NP-MC301XG, NP-CK4155W, NP-CK4255X, NP-CK4155X, NP-CK4055X, NP-CM4150X, NP-CM4050X, NP-CK4155WG, NP-CK4255XG, NP-CK4155XG, NP-CR2165W, NP-CR2305X, NP-CR2275X, NP-CR2165X, NP-CR2155X, NP-CD2115X, NP-CD2105X, NP-CM4151X, NP-CR2276X, NP-CD2116X, NP-P502H, NP-P502W, NP-P452H, NP-P452W

Critical
VulnerabilityMon Dec 22 2025

CVE-2025-15012: SQL Injection in code-projects Refugee Food Management System

Medium
VulnerabilityMon Dec 22 2025

CVE-2025-15013: Stack-based Buffer Overflow in floooh sokol

Medium
VulnerabilityMon Dec 22 2025

CVE-2025-15016: CWE-321 Use of Hard-coded Cryptographic Key in Ragic Enterprise Cloud Database

Critical
VulnerabilityMon Dec 22 2025

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats