Unrated severityNVD Advisory· Published Apr 2, 2025· Updated Apr 15, 2025
CVE-2025-3073
CVE-2025-3073
Description
Inappropriate implementation in Autofill in Google Chrome prior to 135.0.7049.52 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Affected products
7- osv-coords5 versionspkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/gn&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/chromium&distro=SUSE%20Package%20Hub%2015%20SP6pkg:rpm/suse/gn&distro=SUSE%20Package%20Hub%2015%20SP6
< 135.0.7049.52-bp156.2.102.2+ 4 more
- (no CPE)range: < 135.0.7049.52-bp156.2.102.2
- (no CPE)range: < 135.0.7049.52-2.1
- (no CPE)range: < 0.20250306-bp156.2.6.1
- (no CPE)range: < 135.0.7049.52-bp156.2.102.2
- (no CPE)range: < 0.20250306-bp156.2.6.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.