PT-2025-21205 · Google+4 · Google Chrome+4

Published

2025-05-05

·

Updated

2025-12-08

·

CVE-2025-4664

CVSS v2.0

5.0

Medium

AV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chromium versions prior to 136.0.7103.113
Description A high-severity vulnerability in Chromium allows remote attackers to leak cross-origin data via crafted HTML pages, potentially leading to full account takeover. The vulnerability is caused by insufficient policy enforcement in the Loader component. It is being actively exploited in the wild, and users are urged to update their browsers immediately.
Recommendations To resolve the issue, update Chromium to version 136.0.7103.113 or later. As a temporary workaround, consider restricting access to the vulnerable Loader component until a patch is available. Avoid using Chromium until the update is applied, as the vulnerability can be exploited by visiting a malicious website.

Exploit

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6902
BDU:2025-05679
CVE-2025-4664
DSA-5920-1
MGASA-2025-0159
OPENSUSE-SU-2025:15143-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os