CVE-2025-4609
BaseFortify
Publication date: 2025-08-22
Last updated on: 2025-08-25
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 136.0.7103.113 (exc) | |
| microsoft | windows | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves an incorrect handle being provided in certain unspecified circumstances within the Mojo component of Google Chrome on Windows versions prior to 136.0.7103.113. This flaw allows a remote attacker to potentially escape the browser's sandbox by using a malicious file.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow a remote attacker to break out of the browser's sandbox environment, potentially gaining higher privileges on the affected system. This could lead to unauthorized access or control over the system beyond the browser.