CVE-2025-8582 PUBLISHED

Assigner: Chrome
Reserved: 05.08.2025 Published: 07.08.2025 Updated: 11.08.2025

Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

Product Status

Vendor Google
Product Chrome
Versions
  • affected from 139.0.7258.66 to 139.0.7258.66 (excl.)

References

Problem Types

  • Insufficient validation of untrusted input