CVE-2025-11213: Inappropriate implementation in Omnibox
Chromium: CVE-2025-11213 Inappropriate implementation in Omnibox
Other sources
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141.0.7390.54 - Upgrade
Upgrade
Google Chrome on Androidto a version that resolves this vulnerability.Fixed in 141.0.7390.54
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11213?
The severity of CVE-2025-11213 is classified as high due to its potential impact on user privacy and security.
How do I fix CVE-2025-11213?
To fix CVE-2025-11213, ensure that you are using the latest version of Microsoft Edge (Chromium-based) or apply the relevant security updates.
Which versions of Edge are affected by CVE-2025-11213?
CVE-2025-11213 affects Microsoft Edge (Chromium-based) prior to version 141.0.3537.57.
What is the cause of CVE-2025-11213?
CVE-2025-11213 is caused by an inappropriate implementation in the Omnibox feature of Chromium.
Is CVE-2025-11213 specific to Microsoft Edge?
Yes, CVE-2025-11213 has been identified in Microsoft Edge as it utilizes the Chromium codebase.