What the vulnerability does

01Description

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

Key dates

02Disclosure timeline

August 7, 2025 CVE published
August 11, 2025 Record updated