CVE-2025-11209: Inappropriate implementation in Omnibox
Chromium: CVE-2025-11209 Inappropriate implementation in Omnibox
Other sources
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141.0.7390.54 - Upgrade
Upgrade
Google Chrome on Androidto a version that resolves this vulnerability.Fixed in 141.0.7390.54
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2025-11209?
CVE-2025-11209 is a vulnerability in Chromium related to inappropriate implementation in Omnibox, affecting Chromium-based browsers.
What is the severity of CVE-2025-11209?
The severity of CVE-2025-11209 has not been explicitly stated but it may impact user privacy and security depending on its exploitation.
How do I fix CVE-2025-11209?
To fix CVE-2025-11209, ensure that you are using the latest version of Microsoft Edge (Chromium-based) or any Chromium-based browser that has addressed this vulnerability.
Which versions of Microsoft Edge are affected by CVE-2025-11209?
CVE-2025-11209 affects Microsoft Edge versions prior to 141.0.3537.57.
How was CVE-2025-11209 discovered?
CVE-2025-11209 was discovered as a result of vulnerabilities reported in the Chromium browser engine, prompting updates from Google and Microsoft.