Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-12444

CVE-2025-12444: Google Chrome XSS Vulnerability

CVE-2025-12444 is an XSS vulnerability in Google Chrome's Fullscreen UI that enables UI spoofing attacks through crafted HTML pages. This article covers the technical details, affected versions, impact, and mitigation.

Published:

CVE-2025-12444 Overview

CVE-2025-12444 is a user interface spoofing vulnerability in Google Chrome versions prior to 142.0.7444.59. The flaw resides in Chrome's Fullscreen UI implementation, where incorrect security indicators allow a remote attacker to spoof interface elements. Exploitation requires a victim to visit a crafted HTML page and perform specific UI gestures. Chromium's internal severity rating is Low, and the CWE classification is [CWE-306] Missing Authentication for Critical Function. The vulnerability affects Chrome across Windows, macOS, and Linux platforms. No known exploitation in the wild has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.

Critical Impact

A remote attacker can spoof browser security UI in fullscreen mode, potentially tricking users into disclosing credentials or sensitive information through a phishing-style interface.

Affected Products

  • Google Chrome prior to 142.0.7444.59
  • Chrome on Microsoft Windows
  • Chrome on Apple macOS and Linux

Discovery Timeline

  • 2025-11-10 - CVE-2025-12444 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-12444

Vulnerability Analysis

The vulnerability stems from incorrect security UI rendering in Chrome's Fullscreen mode. When a page enters fullscreen through the Fullscreen API, the browser is expected to display clear security indicators that inform the user of the fullscreen transition and the originating domain. In vulnerable builds, these indicators can be manipulated or bypassed through specific user gesture sequences.

An attacker hosting a crafted HTML page can render controlled content that visually mimics trusted browser chrome, operating system dialogs, or authentication prompts. Because fullscreen removes the address bar and system UI, victims lose the standard visual context needed to distinguish legitimate interface elements from attacker-drawn content. The result is a user interface confusion condition that facilitates credential phishing or social engineering.

Root Cause

The root cause is a logic flaw in the Fullscreen UI security surface, tracked as [CWE-306] Missing Authentication for Critical Function. Chrome fails to consistently enforce security UI presentation when specific gesture sequences occur during fullscreen entry. See the Chromium Issue Tracker Entry for technical context.

Attack Vector

Exploitation requires network delivery of a crafted HTML page and user interaction. The attacker must convince the victim to visit an attacker-controlled site and perform specific UI gestures that trigger the flawed fullscreen behavior. Attack complexity is high because the required gesture sequence must be reliably reproduced by the target. No authentication is required, but the attack cannot proceed without user interaction. Impact is limited to confidentiality and availability of the browsing session through spoofed interface content. See the Google Chrome Update Announcement for vendor context.

Detection Methods for CVE-2025-12444

Indicators of Compromise

  • Chrome browser versions below 142.0.7444.59 running in the environment
  • Web traffic to unfamiliar domains immediately followed by user credential submission to those same domains
  • Endpoint logs showing repeated fullscreen API invocations from a single untrusted origin

Detection Strategies

  • Inventory Chrome installations across the fleet and flag any build older than 142.0.7444.59 for remediation
  • Correlate browser telemetry with proxy logs to identify sessions that entered fullscreen on newly registered or low-reputation domains
  • Monitor phishing report submissions and help desk tickets referencing unexpected browser prompts or login screens

Monitoring Recommendations

  • Ingest Chrome version telemetry into your SIEM and alert on installations that lag the current stable channel
  • Track outbound HTTPS connections to domains flagged for UI spoofing or credential phishing
  • Review user-reported phishing incidents for patterns consistent with fullscreen-based spoofing

How to Mitigate CVE-2025-12444

Immediate Actions Required

  • Update all Chrome installations to version 142.0.7444.59 or later on Windows, macOS, and Linux endpoints
  • Verify that Chrome auto-update is enabled and functioning across the environment
  • Communicate to users that fullscreen pages requesting credentials or system-style prompts should be exited using the Esc key

Patch Information

Google released the fix in the Chrome Stable channel update announced on October 28, 2025. The patched version is 142.0.7444.59 and later. Refer to the Google Chrome Update Announcement for release notes and the Chromium Issue Tracker Entry for the underlying bug reference.

Workarounds

  • Deploy enterprise policy to restrict the Fullscreen API on untrusted sites where feasible
  • Train users to recognize fullscreen-based phishing and to press Esc before entering credentials into any full-screen interface
  • Use enterprise browser management to enforce mandatory version updates and disable outdated Chrome builds

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.