CVE-2025-0443

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 15, 2025
CWE ID 79

Summary

CVE-2025-0443 is a medium severity vulnerability affecting Google Chrome versions prior to 132.0.6834.83. The issue stems from insufficient data validation in the browser's extensions. A malicious actor could exploit this vulnerability by designing a crafted HTML page that induces specific UI gestures from users. Successful exploitation would grant the attacker privilege escalation capabilities. Users are advised to update their Chrome browsers to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share