CVE-2025-11210: channel information leakage in Tab.
Chromium: CVE-2025-11210 Side-channel information leakage in Tab
Other sources
Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11210?
CVE-2025-11210 has been classified as a medium-severity vulnerability due to the potential for side-channel information leakage.
How do I fix CVE-2025-11210?
To fix CVE-2025-11210, users should update their Chromium-based Microsoft Edge browser to the latest version that addresses this vulnerability.
Which versions of Edge are affected by CVE-2025-11210?
Microsoft Edge versions up to 141.0.3537.57 are affected by CVE-2025-11210.
Who is responsible for addressing CVE-2025-11210?
CVE-2025-11210 is addressed by the Chromium project, which is maintained by Google, and affects Chromium-based browsers like Microsoft Edge.
What type of vulnerability is CVE-2025-11210?
CVE-2025-11210 is a side-channel information leakage vulnerability that could allow attackers to gain unauthorized access to sensitive data.