Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
https://issues.chromium.org/issues/415810136
https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html
Published: 2025-05-14
Updated: 2025-05-16
Known Exploited Vulnerability (KEV)
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: Medium
Base Score: 4.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Severity: Medium
EPSS: 0.00059
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored