PT-2025-26787 · Google+2 · Google Chrome+2

Ameen Basha M K

·

Published

2025-06-24

·

Updated

2025-07-18

·

CVE-2025-6557

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Google Chrome versions prior to 138.0.7204.49
Description: Insufficient data validation in DevTools in Google Chrome on Windows allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. The issue has a security severity of Low.
Recommendations: For versions prior to 138.0.7204.49, update to version 138.0.7204.49 or later to resolve the issue. As a temporary workaround, consider restricting access to DevTools until the update is applied. Avoid using crafted HTML pages that could exploit this issue until the update is installed.

Fix

RCE

Clickjacking

Weakness Enumeration

Related Identifiers

ALT-PU-2025-9065
BDU:2025-09102
CVE-2025-6557
DSA-5952-1
OPENSUSE-SU-2025:15210-1

Affected Products

Alt Linux
Debian
Google Chrome