CVE-2025-12908
published 2025-11-08CVE-2025-12908: Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing…
PriorityP426medium5.4CVSS 3.1
AVNACLPRNUIRSUCLINAL
EPSS
0.18%
8.0th percentile
Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | — | — |
| chrome | < 140.0.7339.80 | 140.0.7339.80 | |
| chrome | >= 140.0.7339.80 < 140.0.7339.80 | 140.0.7339.80 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
vendor_debian5.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3jxx-m7vj-jgc2: Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140
ghsa_unreviewed·2025-11-08
CVE-2025-12908 [MEDIUM] CWE-20 GHSA-3jxx-m7vj-jgc2: Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140
Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Chrome
Stable Channel Update for Desktop: CVE-2025-12908
vendor_chrome·2025-09-02·CVSS 5.4
CVE-2025-12908 [LOW] Stable Channel Update for Desktop: CVE-2025-12908
Stable Channel Update for Desktop
CVE-2025-12908: Insufficient validation of untrusted input in Downloads. Reported by Abhishek Kumar on 2025-05-31 [$1000][ 361116749 ] Low CVE-2025-12909: Insufficient policy enforcement in Devtools
Reported by Noam Gaash on 2024-08-20 [TBD][ 434977743 ] Low CVE-2025-12910: Inappropriate implementation in Passkeys
Severity: low
Debian
CVE-2025-12908: chromium - Insufficient validation of untrusted input in Downloads in Google Chrome on Andr...
vendor_debian·2025·CVSS 5.4
CVE-2025-12908 [MEDIUM] CVE-2025-12908: chromium - Insufficient validation of untrusted input in Downloads in Google Chrome on Andr...
Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2025-11-08
Published