Skip to main content

Insufficient Visual Distinction of Homoglyphs Presented to User

CVE-2025-0996

Severity Medium
Score 5.4/10

Summary

Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • REQUIRED
  • NONE
  • LOW
  • NONE

CWE-1007 - Insufficient Visual Distinction of Homoglyphs Presented to User

The software displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.

Advisory Timeline

  • Published