Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop.html | vendor advisory release notes |
https://issues.chromium.org/issues/411544197 | issue tracking permissions required |