Google Chrome UI Spoofing Vulnerability in Downloads Component on Android

Vulnerability

A UI spoofing vulnerability has been identified in the Downloads feature of Google Chrome on Android, affecting versions prior to 140.0.7339.80. This vulnerability allows remote attackers to manipulate user interface elements through a specially crafted HTML page.

Impact

Exploitation of this vulnerability could lead to successful UI spoofing, where an attacker can create a misleading interface that deceives the user.

Remediation

Users can update to Google Chrome version 140.0.7339.80 or later to address this vulnerability.

Added: Sep 3, 2025, 5:25 PM
Updated: Sep 3, 2025, 6:28 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.