PT-2025-45516 · Google+2 · Google Chrome+2
Published
2025-09-02
·
Updated
2026-01-19
·
CVE-2025-12907
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 140.0.7339.80
Description
A flaw exists in Google Chrome's Devtools due to insufficient validation of untrusted input. This can allow a remote attacker to execute arbitrary code through user interaction within Devtools. The issue stems from the 'Copy as cURL (cmd)' feature in DevTools not sanitizing the tab character (
t). Because cmd.exe interprets tabs as delimiters, an attacker can inject a tab, a command separator (like '&'), and a newline character into the payload. This causes the cURL argument to be ignored and allows the execution of additional arbitrary commands when the text is pasted into the command line. A proof-of-concept involves a malicious HTML page that, when copied as cURL(cmd) and pasted into the command line, executes calc.exe.Recommendations
Update Google Chrome to version 140.0.7339.80 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Google Chrome
Red Os