CVE-2025-23964
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 79
Summary
CVE-2025-23964 is a Cross-site Scripting (XSS) vulnerability affecting Google Plus from an unknown version up to 1.0.2. Attackers can exploit this Improper Neutralization of Input during Web Page Generation issue to inject malicious scripts into Google Plus web pages, potentially stealing user data or taking control of user sessions. This represents a significant security risk and Google Plus users are urged to apply patches or updates as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.