Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities
ID: d442a60b-93c2-5ac3-8859-2814fa46c5a6
STIX ID: report--d442a60b-93c2-5ac3-8859-2814fa46c5a6
Feed Name: Bleeping Computer
Threat Score
Ox Security found that Cursor and Windsurf — Electron-based IDEs forked from VS Code — ship outdated Chromium/V8 builds containing at least 94 known CVEs; researchers demonstrated a proof-of-concept exploit for CVE-2025-7656 that causes a renderer crash (DoS) and warn that RCE is possible via extensions, deeplinks, or poisoned documentation, potentially affecting ~1.8M developers while vendors have not remediated the issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
