Inappropriate implementation in Extensions API in Google...
Moderate severity
Unreviewed
Published
Feb 4, 2025
to the GitHub Advisory Database
•
Updated Feb 8, 2025
Description
Published by the National Vulnerability Database
Feb 4, 2025
Published to the GitHub Advisory Database
Feb 4, 2025
Last updated
Feb 8, 2025
Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)
References