CVE-2025-13635
vulnerability analysis and mitigation

Overview

CVE-2025-13635 is a low-severity UI spoofing vulnerability caused by an inappropriate implementation in the Downloads feature of Google Chrome. It allows a local attacker to perform UI spoofing via a crafted HTML page. The vulnerability affects all Google Chrome versions prior to 143.0.7499.40/41 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It was reported by security researcher Hafiizh on March 24, 2025, and publicly disclosed on December 2, 2025, when Chrome 143 was promoted to the stable channel. It carries a CVSS v3.1 base score of 4.4 (Medium) (Chrome Releases, Microsoft MSRC).

Technical details

The root cause is classified as CWE-290 (Authentication Bypass by Spoofing), stemming from an inappropriate implementation in Chrome's Downloads subsystem. A local attacker can craft a malicious HTML page that manipulates how the Downloads UI is rendered or presented to the user, causing the interface to display misleading or spoofed information. Exploitation requires user interaction — specifically, a user must open or interact with the crafted HTML page. The Chromium issue tracker entry (ID 405727341) is currently restricted pending broader user adoption of the patch (Chrome Releases).

Impact

Successful exploitation allows a local attacker to manipulate Chrome's Downloads UI, potentially tricking users into taking unintended actions such as accepting malicious file downloads or misidentifying the source or nature of a download. The primary impact is on integrity and user trust, with limited confidentiality and availability impact (CVSS scores of Low for both). This vulnerability does not enable remote code execution or privilege escalation on its own, but could serve as a component in a broader social engineering attack chain (Chrome Releases).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability has an EPSS score of approximately 0.005% (0.000050), indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Google rated this vulnerability as Low severity from a Chromium security perspective, and the bug was awarded a $3,000 bounty to the reporting researcher (Chrome Releases).

Exploitation steps

  1. Craft malicious HTML page: An attacker with local access creates a specially crafted HTML page that exploits the inappropriate implementation in Chrome's Downloads feature to manipulate the Downloads UI presentation.
  2. Deliver to target: The attacker places the crafted HTML file on the target system or convinces the user to open it via a local file path or internal network share.
  3. User interaction: The victim opens the crafted HTML page in a vulnerable version of Chrome (prior to 143.0.7499.40/41), triggering the UI spoofing behavior.
  4. UI manipulation: The Downloads UI is manipulated to display misleading information — for example, misrepresenting a file's name, type, or origin — potentially tricking the user into accepting or executing a malicious download (Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 143.0.7499.40 (Linux) and 143.0.7499.40/41 (Windows/Mac), released on December 2, 2025. Users should update Chrome to version 143.0.7499.41 or later via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a general precaution, users should avoid opening HTML files from untrusted local sources. Enterprise administrators should enforce browser update policies to ensure timely patching (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 143 release received broad coverage from security media outlets including CyberSecurityNews, GBHackers, Forbes, and BleepingComputer, primarily in the context of the full 13-vulnerability patch batch rather than CVE-2025-13635 specifically. Forbes noted the update as a "crucial" one urging Chrome's approximately 3 billion users to act. The vulnerability itself, rated Low severity, did not generate significant standalone commentary given its limited impact scope and local-only attack vector.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 143.0.7499.40-1~deb12u1

Fixed

sid

chromium: 143.0.7499.40-1

Fixed

trixie

chromium: 143.0.7499.40-1~deb13u1

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management