
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13635 is a low-severity UI spoofing vulnerability caused by an inappropriate implementation in the Downloads feature of Google Chrome. It allows a local attacker to perform UI spoofing via a crafted HTML page. The vulnerability affects all Google Chrome versions prior to 143.0.7499.40/41 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It was reported by security researcher Hafiizh on March 24, 2025, and publicly disclosed on December 2, 2025, when Chrome 143 was promoted to the stable channel. It carries a CVSS v3.1 base score of 4.4 (Medium) (Chrome Releases, Microsoft MSRC).
The root cause is classified as CWE-290 (Authentication Bypass by Spoofing), stemming from an inappropriate implementation in Chrome's Downloads subsystem. A local attacker can craft a malicious HTML page that manipulates how the Downloads UI is rendered or presented to the user, causing the interface to display misleading or spoofed information. Exploitation requires user interaction — specifically, a user must open or interact with the crafted HTML page. The Chromium issue tracker entry (ID 405727341) is currently restricted pending broader user adoption of the patch (Chrome Releases).
Successful exploitation allows a local attacker to manipulate Chrome's Downloads UI, potentially tricking users into taking unintended actions such as accepting malicious file downloads or misidentifying the source or nature of a download. The primary impact is on integrity and user trust, with limited confidentiality and availability impact (CVSS scores of Low for both). This vulnerability does not enable remote code execution or privilege escalation on its own, but could serve as a component in a broader social engineering attack chain (Chrome Releases).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.005% (0.000050), indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Google rated this vulnerability as Low severity from a Chromium security perspective, and the bug was awarded a $3,000 bounty to the reporting researcher (Chrome Releases).
Google has addressed this vulnerability in Chrome 143.0.7499.40 (Linux) and 143.0.7499.40/41 (Windows/Mac), released on December 2, 2025. Users should update Chrome to version 143.0.7499.41 or later via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a general precaution, users should avoid opening HTML files from untrusted local sources. Enterprise administrators should enforce browser update policies to ensure timely patching (Chrome Releases, Microsoft MSRC).
The Chrome 143 release received broad coverage from security media outlets including CyberSecurityNews, GBHackers, Forbes, and BleepingComputer, primarily in the context of the full 13-vulnerability patch batch rather than CVE-2025-13635 specifically. Forbes noted the update as a "crucial" one urging Chrome's approximately 3 billion users to act. The vulnerability itself, rated Low severity, did not generate significant standalone commentary given its limited impact scope and local-only attack vector.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."