CVE-2025-4664

MEDIUM EXPLOITED

Google Chrome <136.0.7103.113 - Info Disclosure

Title source: llm

Description

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Exploits (5)

nomisec WORKING POC 13 stars
by Leviticus-Triage · poc
https://github.com/Leviticus-Triage/ChromSploit-Framework
nomisec WORKING POC 3 stars
by amalmurali47 · client-side
https://github.com/amalmurali47/cve-2025-4664
nomisec WORKING POC
by speinador · poc
https://github.com/speinador/CVE-2025-4664
github WORKING POC
by manus-use · postscriptpoc
https://github.com/manus-use/cve-pocs/tree/main/chrome-CVE-2025-4664
vulncheck_xdb WORKING POC
client-side
https://github.com/speinador/CVE-2025-4664-

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Exploitation Intel

VulnCheck KEV 2025-05-14
ENISA EUVD EUVD-2025-14909

Classification

Status published

Affected Products (1)

google/chrome < 136.0.7103.113

Timeline

Published May 14, 2025
Tracked Since Feb 18, 2026