PT-2025-45516 · Google+2 · Google Chrome+2

Published

2025-09-02

·

Updated

2026-01-19

·

CVE-2025-12907

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 140.0.7339.80
Description A flaw exists in Google Chrome's Devtools due to insufficient validation of untrusted input. This can allow a remote attacker to execute arbitrary code through user interaction within Devtools. The issue stems from the 'Copy as cURL (cmd)' feature in DevTools not sanitizing the tab character (t). Because cmd.exe interprets tabs as delimiters, an attacker can inject a tab, a command separator (like '&'), and a newline character into the payload. This causes the cURL argument to be ignored and allows the execution of additional arbitrary commands when the text is pasted into the command line. A proof-of-concept involves a malicious HTML page that, when copied as cURL(cmd) and pasted into the command line, executes calc.exe.
Recommendations Update Google Chrome to version 140.0.7339.80 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-14028
CVE-2025-12907
DSA-5993-1

Affected Products

Debian
Google Chrome
Red Os