User Interface (UI) Misrepresentation of Critical Information Affecting chromium package, versions [,140.0.7339.80)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-CHROMIUM-13865280
  • published11 Nov 2025
  • disclosed7 Nov 2025
  • creditUnknown

Introduced: 7 Nov 2025

NewCVE-2025-12911  (opens in a new tab)
CWE-451  (opens in a new tab)

How to fix?

Upgrade chromium to version 140.0.7339.80 or higher.

Overview

Affected versions of this package are vulnerable to User Interface (UI) Misrepresentation of Critical Information due to the CSS property inheritance handling in the HTMLPermissionElement. An attacker can perform UI spoofing by crafting an HTML page that applies text-decoration CSS properties to parent elements of the permission element, causing the decoration to propagate to the permission element and potentially mislead users about the appearance or authenticity of the permission prompt.

References

CVSS Base Scores

version 4.0
version 3.1