PT-2025-22906 · Google · Web Designer App+1

Bálint Magyar

·

Published

2025-05-26

·

Updated

2025-08-01

·

CVE-2025-4613

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Web Designer versions prior to 16.3.0.0407
Description The issue allows an attacker to achieve remote code execution by tricking users into downloading a malicious ad template. This is due to path traversal in Google Web Designer's template handling on Windows.
Recommendations For versions prior to 16.3.0.0407, update to version 16.3.0.0407 or later to resolve the issue. As a temporary workaround, consider avoiding the download of ad templates from untrusted sources until the update is applied. Restrict access to template handling features in Google Web Designer to minimize the risk of exploitation.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-4613

Affected Products

Web Designer App
Web Designer