CVE-2025-13635
BaseFortify
Publication date: 2025-12-02
Last updated on: 2025-12-04
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 143.0.7499.40 (exc) | |
| chrome | to 143.0.7499.40 (exc) | |
| apple | macos | * |
| microsoft | windows | * |
| linux | linux_kernel | From 5.15.160 (inc) to 5.16 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an inappropriate implementation in the Downloads feature of Google Chrome versions prior to 143.0.7499.41. It allows a local attacker to perform UI spoofing by using a crafted HTML page, potentially misleading users by displaying fake user interface elements.
How can this vulnerability impact me? :
The vulnerability can impact you by enabling a local attacker to spoof the user interface within the Downloads section of Google Chrome. This could trick users into believing they are interacting with legitimate browser elements, potentially leading to confusion or unintended actions, although the severity is considered low.