CVE-2025-8579

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-8579
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-8579.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-8579
Downstream
Published
2025-08-07T02:15:27Z
Modified
2025-08-14T10:01:31Z
Summary
[none]
Details

Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

References

Affected packages