CVE-2025-0451User Interface (UI) Misrepresentation of Critical Information in Google Chrome

Severity
6.3MEDIUMNVD
EPSS
0.3%
top 51.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateFeb 21

Description

Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages4 packages

CVEListV5google/chrome133.0.6943.53133.0.6943.53
NVDgoogle/chrome< 133.0.6943.53
Debianchromium/chromium< 133.0.6943.53-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-qjjm-cjhw-r68m: Inappropriate implementation in Extensions API in Google Chrome prior to 1332025-02-04
OSV
CVE-2025-0451: Inappropriate implementation in Extensions API in Google Chrome prior to 1332025-02-04
CVEList
CVE-2025-0451: Inappropriate implementation in Extensions API in Google Chrome prior to 1332025-02-04

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex - M133: CVE-2025-04512025-02-21
Palo Alto
PAN-SA-2025-0004 Chromium: Monthly Vulnerability Update (February 2025)2025-02-12
Microsoft
Chromium: CVE-2025-0451 Inappropriate implementation in Extensions API2025-02-11
Debian
CVE-2025-0451: chromium - Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6...2025

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws2025-02-11
CVE-2025-0451 — Google Chrome vulnerability | cvebase