Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
https://thehackernews.com/2025/07/urgent-google-releases-critical-chrome.html
https://www.theregister.com/2025/06/03/google_chrome_zero_day_emergency_fix/
https://thehackernews.com/2025/12/chrome-targeted-by-active-in-wild.html
https://thehackernews.com/2025/11/google-issues-security-fix-for-actively.html
https://www.theregister.com/2025/09/18/google_emergency_patch_chrome_0_day/
https://thehackernews.com/2025/09/google-patches-chrome-zero-day-cve-2025.html
https://www.securityweek.com/chrome-138-update-patches-zero-day-vulnerability/
https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html
https://hackread.com/chrome-0-day-cve-2025-4664-windows-linux-browser-activity/
https://github.com/mingijunggrape/CVE-2025-4664
https://github.com/Leviticus-Triage/ChromSploit-Framework
https://github.com/speinador/CVE-2025-4664-
https://github.com/speinador/CVE-2025-4664
https://github.com/korden-c/CVE-2025-4664
https://github.com/doomygloom/CVE-2025-4664
https://github.com/PuddinCat/GithubRepoSpider
https://issues.chromium.org/issues/415810136
https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html
Published: 2025-05-14
Updated: 2025-06-06
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 4.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Severity: Medium
EPSS: 0.00059
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored