
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-8582 is an insufficient validation of untrusted input vulnerability in the DOM/Core component of Google Chrome that allows a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. The vulnerability was originally reported by an anonymous researcher on 2017-10-31 and was publicly disclosed on August 5–7, 2025, when Google released Chrome 139.0.7258.66 to address it. All versions of Google Chrome prior to 139.0.7258.66 are affected, as is Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Red Hat Bugzilla).
The root cause is improper input validation (CWE-20) in Chrome's Core/DOM processing, combined with UI misrepresentation of critical information (CWE-451). The flaw enables a remote attacker to craft a malicious HTML page that manipulates how the browser's Omnibox (address bar) displays the current URL, effectively spoofing the origin shown to the user. Exploitation requires user interaction — specifically, a victim must visit a specially crafted web page — but no authentication or elevated privileges are needed. The Chromium issue tracker references bug ID 40089450, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, Red Hat Bugzilla).
Successful exploitation allows an attacker to spoof the URL displayed in Chrome's Omnibox, potentially deceiving users into believing they are visiting a legitimate site when they are not. This primarily affects integrity and enables phishing, credential harvesting, or social engineering attacks by masking a malicious page's true origin. There is no direct confidentiality or availability impact from this vulnerability itself, but the spoofing capability can serve as a facilitator for more severe follow-on attacks (Red Hat Bugzilla, Chrome Releases).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-8582. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.047% (0.000470), indicating a very low probability of exploitation in the near term. The bug was originally reported in October 2017 and took until 2025 to be patched, suggesting it was a long-standing low-priority issue with no known weaponization (Chrome Releases).
Google has patched this vulnerability in Chrome 139.0.7258.66 (Linux) and 139.0.7258.66/67 (Windows and Mac), released on August 5, 2025. Microsoft has also released a corresponding update for Edge (Chromium-based). Users and administrators should update Chrome and Edge to the latest available versions immediately. No configuration-based workaround is available; updating to the patched version is the only remediation. Downstream distributions (Debian, openSUSE, Fedora, Red Hat) have also released updated Chromium packages (Chrome Releases, Microsoft MSRC, Red Hat Bugzilla).
The vulnerability received limited industry attention given its Low severity rating and narrow impact (UI spoofing only). Coverage was largely confined to routine patch-tracking publications and Linux distribution security advisories (Debian DSA-5971, openSUSE, Fedora). The notable detail highlighted by some outlets is that the bug was originally reported in October 2017 — nearly eight years before it was patched — which drew minor commentary about Chrome's vulnerability triage and patch timelines (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."