CVE-2025-25078

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 7, 2025
CWE ID 79

Summary

CVE-2025-25078 is a Cross-site Scripting (XSS) vulnerability affecting Google Earth Embed. Maliciously crafted input data can be improperly neutralized during web page generation, allowing an attacker to inject and execute malicious scripts in a user's browser. This issue puts users at risk of data theft or unauthorized access when viewing Google Earth Embed versions from n/a through 1.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share