logo

Google fixes high severity Chrome flaw with public exploit

ID: 51c4761b-8f77-53b8-b667-a25518c7efb2

STIX ID: report--51c4761b-8f77-53b8-b667-a25518c7efb2

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-05-15

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Google released emergency updates to patch CVE-2025-4664, an insufficient policy enforcement in Chrome's Loader that can leak cross-origin data (including OAuth query parameters) via the Link header and referrer-policy, potentially enabling account takeover; Google reported an exploit exists in the wild and issued Stable Desktop patches (136.0.7103.113/114).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.