CVE-2025-11209
BaseFortify
Publication date: 2025-11-06
Last updated on: 2025-11-13
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 141.0.7390.54 (exc) | |
| android | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an inappropriate implementation in the Omnibox (URL bar) of Google Chrome on Android versions prior to 141.0.7390.54. It allows a remote attacker to spoof the contents of the Omnibox by using a crafted HTML page, making it appear as if the browser is displaying a different URL than it actually is.
How can this vulnerability impact me? :
This vulnerability can impact you by enabling attackers to deceive you about the website you are visiting. By spoofing the URL bar, attackers can trick you into believing you are on a legitimate site when you are actually on a malicious one, potentially leading to phishing attacks or other security risks.