CVE-2025-8577

Source
https://cve.org/CVERecord?id=CVE-2025-8577
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8577.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-8577
Downstream
Published
2025-08-07T02:15:27Z
Modified
2025-08-14T10:01:15Z
Summary
[none]
Details

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

References

Affected packages