CVE-2025-4215 describes a problematic vulnerability in gorhill uBlock Origin up to version 1.63.3b16, specifically within the currentStateChanged function of the UI component, affecting Debian-based systems. This vulnerability stems from inefficient regular expression complexity, which could lead to a denial of service. While remotely exploitable, the attack complexity is high, and the overall CVSS score is low (3.7), indicating a limited impact (availability only). There is no evidence of active exploitation, and despite public disclosure of the exploit, there is no known exploit intelligence (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.63.3CPE matchmatch criteria | cpe:2.3:a:ublockorigin:ublock_origin:*:*:*:*:*:*:*:* | ||
1.63.3CPE matchmatch criteria | cpe:2.3:a:ublockorigin:ublock_origin:1.63.3:beta1:*:*:*:*:*:* | ||
1.63.3CPE matchmatch criteria | cpe:2.3:a:ublockorigin:ublock_origin:1.63.3:beta10:*:*:*:*:*:* | ||
1.63.3CPE matchmatch criteria | cpe:2.3:a:ublockorigin:ublock_origin:1.63.3:beta11:*:*:*:*:*:* | ||
1.63.3CPE matchmatch criteria | cpe:2.3:a:ublockorigin:ublock_origin:1.63.3:beta12:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.