Security Advisory

CVE-2025-7021

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-10 19:09:40
Last updated 2025-07-10 20:29:32
Assigner Google
CVSS score not scored
State PUBLISHED

Description

Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with overlaid fake browser controls and a distracting element (like a cookie consent screen) to obscure fullscreen notifications, tricking the user into interacting with the malicious site.