CVE-2025-8582: Low Insufficient validation of untrusted input in DOM.
Chromium: CVE-2025-8582 Insufficient validation of untrusted input in DOM
Other sources
Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
— MITRE
Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 139.0.7258.66 - Upgrade
Upgrade
Google Chrome / Chromiumto a version that resolves this vulnerability.Fixed in 139.0.7258.66 - Compensating control
Because the Chromium issue allows spoofing of the Omnibox via crafted HTML, reduce risk by treating unfamiliar/unknown URLs as untrusted and avoid interacting with links or pages that may be used to spoof the URL bar.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8582?
The severity of CVE-2025-8582 is classified as Low.
How do I fix CVE-2025-8582?
To fix CVE-2025-8582, update Google Chrome to version 139.0.7258.66 or later.
What type of vulnerability is CVE-2025-8582?
CVE-2025-8582 is an insufficient validation of untrusted input vulnerability.
Can CVE-2025-8582 be exploited remotely?
Yes, a remote attacker can exploit CVE-2025-8582 to spoof the contents of the Omnibox.
What kind of user impact does CVE-2025-8582 have?
CVE-2025-8582 can mislead users by displaying crafted URLs in the Omnibox.