CVE-2025-12439
MEDIUMGoogle Chrome < 142.0.7444.59 - Weak Encryption
Title source: ruleDescription
Inappropriate implementation in App-Bound Encryption in Google Chrome on Windows prior to 142.0.7444.59 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)
Scores
CVSS v3
5.5
EPSS
0.0000
EPSS Percentile
0.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-326
Status
published
Affected Products (1)
google/chrome
< 142.0.7444.59
Timeline
Published
Nov 10, 2025
Tracked Since
Feb 18, 2026