CVE-2025-5067: Inappropriate implementation in Tab Strip
Chromium: CVE-2025-5067 Inappropriate implementation in Tab Strip
Other sources
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5067?
The severity of CVE-2025-5067 is classified as Low.
How do I fix CVE-2025-5067?
To fix CVE-2025-5067, update Google Chrome to version 137.0.7151.55 or later.
What type of attack does CVE-2025-5067 involve?
CVE-2025-5067 involves UI spoofing via a crafted HTML page.
Which software is affected by CVE-2025-5067?
CVE-2025-5067 affects Google Chrome versions prior to 137.0.7151.55.
Can CVE-2025-5067 be exploited remotely?
Yes, CVE-2025-5067 can be exploited remotely by an attacker.