CVE-2025-0996
Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.36%
- CWE
- CWE-1007
- Published
- 2025-02-15
- Last modified
- 2026-03-13
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-48760 — Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
- CVE-2026-45064 — Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
- CVE-2025-27611 — base-x homograph attack allows Unicode lookalike characters to bypass validation.