CVE Vulnerabilities

CVE-2025-8881

Incorrect Implementation of Authentication Algorithm

Published: Aug 13, 2025 | Modified: Aug 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Weakness

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Affected Software

Name Vendor Start Version End Version
Chrome Google * 139.0.7258.127 (excluding)
Chromium-browser Ubuntu upstream *

References