
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14373 is an inappropriate implementation vulnerability in the Toolbar component of Google Chrome on Android that allows a remote attacker to perform domain spoofing via a crafted HTML page. It was reported by security researcher Khalil Zhani on 2025-11-18 and publicly disclosed on December 10, 2025, as part of a Chrome stable channel update. Affected versions include Google Chrome prior to 143.0.7499.109/110 and Microsoft Edge Chromium (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified under CWE-290 (Authentication Bypass by Spoofing) and CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), rooted in an inappropriate implementation within Chrome's Toolbar component on Android. A remote attacker can craft a malicious HTML page that manipulates the browser's toolbar to display a spoofed domain, misleading users about the true origin of the content they are viewing. Exploitation requires user interaction — specifically, a victim must visit or be redirected to the attacker-controlled page. The Chromium issue tracker references bug 461532432 for this vulnerability (Chrome Releases, ENISA EUVD).
Successful exploitation allows a remote attacker to spoof the domain displayed in Chrome's address bar/toolbar on Android, potentially deceiving users into believing they are on a legitimate website when they are not. The primary impact is on confidentiality (rated Low by CVSS), as users may be tricked into submitting credentials or sensitive information to a phishing page. There is no direct integrity or availability impact, and the vulnerability's scope is unchanged, limiting blast radius to the affected browser session (Chrome Releases, ENISA EUVD).
Google has released a fix in Chrome stable channel version 143.0.7499.109 for Linux and 143.0.7499.109/.110 for Windows/Mac, which addresses CVE-2025-14373 along with two other vulnerabilities. Microsoft has also released a corresponding update for Edge Chromium. Users should update Google Chrome and Microsoft Edge to the latest available versions immediately via the browser's built-in update mechanism. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).
Coverage of this vulnerability was largely overshadowed by the co-patched CVE-2025-14174 (ANGLE zero-day), which Google confirmed was actively exploited in the wild. Several security outlets including The Hacker News, Security Affairs, Infosecurity Magazine, and The Register reported on the December 10, 2025 Chrome update batch, with most attention directed at the High-severity ANGLE flaw rather than CVE-2025-14373 specifically. The CIS issued an advisory noting multiple vulnerabilities in Google Chrome could allow for arbitrary code execution, referencing the full update bundle (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."