CVE-2025-0996: Inappropriate implementation in Browser UI
Chromium: CVE -2025-0996 Inappropriate implementation in Browser UI
Other sources
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0996?
CVE-2025-0996 has been classified as a high severity vulnerability.
How do I fix CVE-2025-0996?
To fix CVE-2025-0996, update Google Chrome to version 133.0.6943.98 or later, or update Microsoft Edge to version 133.0.3065.69 or later.
Which products are affected by CVE-2025-0996?
CVE-2025-0996 affects Google Chrome and Microsoft Edge (Chromium-based) versions prior to specified updates.
Is CVE-2025-0996 currently being exploited?
As of now, there are no public reports of exploitation in the wild for CVE-2025-0996.
When was CVE-2025-0996 reported?
CVE-2025-0996 was reported and assigned by Chrome in early 2025.