Google fixes high severity Chrome flaw with public exploit
ID: 51c4761b-8f77-53b8-b667-a25518c7efb2
STIX ID: report--51c4761b-8f77-53b8-b667-a25518c7efb2
Feed Name: Bleeping Computer
Threat Score
Google released emergency updates to patch CVE-2025-4664, an insufficient policy enforcement in Chrome's Loader that can leak cross-origin data (including OAuth query parameters) via the Link header and referrer-policy, potentially enabling account takeover; Google reported an exploit exists in the wild and issued Stable Desktop patches (136.0.7103.113/114).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
