CVE-2025-13107: Inappropriate implementation in Compositing
Published Jul 3, 2025
·Updated
Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Credit
Hafiizh
Affected Software
6 affected componentsFixes available
Google Chrome<140.0.7339.80
Google Chrome<140.0.7339.80
140.0.7339.80
All of the following
Google Chrome<140.0.7339.80
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Jul 3, 2025
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Nov 14, 2025
CVE Published
via MITRE·02:29 AM
Data Sourced
via MITRE·02:29 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-13107?
CVE-2025-13107 has a security severity rating of Low.
2
How do I fix CVE-2025-13107?
To fix CVE-2025-13107, update Google Chrome to version 140.0.7339.80 or later.
3
What type of attack does CVE-2025-13107 enable?
CVE-2025-13107 enables a remote attacker to perform UI spoofing via a crafted HTML page.
4
Which versions of Google Chrome are affected by CVE-2025-13107?
Google Chrome versions prior to 140.0.7339.80 are affected by CVE-2025-13107.
5
What component is impacted by CVE-2025-13107?
CVE-2025-13107 impacts the Compositing component in Google Chrome.