VYPR
Medium severity4.3NVD Advisory· Published Nov 14, 2025· Updated Sep 30, 2026

CVE-2025-13107

CVE-2025-13107

Description

Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

Affected products

6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.