CVE-2025-8581 PUBLISHED

Assigner: Chrome
Reserved: 05.08.2025 Published: 07.08.2025 Updated: 07.08.2025

Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

Product Status

Vendor Google
Product Chrome
Versions
  • affected from 139.0.7258.66 to 139.0.7258.66 (excl.)

References

Problem Types

  • Inappropriate implementation