CVE-2025-7021 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture…
Medium CVSS: 6.9

CVE-2025-7021

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with overlaid fake browser controls and a distracting element (like a cookie consent screen) to obscure fullscreen notifications, tricking the user into interacting with the malicious site.
Vendor
Openai
Product
Operator
CWE
CWE-451
Yayın Tarihi
2025-07-10 20:15:28
Güncelleme
2025-07-24 19:13:23
Source Identifier
cve-coordination@google.com
KEV Date Added
-

Kategoriler

Referanslar