CVE-2025-11207 is a medium-severity side-channel information leakage vulnerability in Google Chrome versions prior to 141.0.7390.54, affecting multiple operating systems including Apple, Google, Linux, and Microsoft. This flaw allows a remote attacker to perform arbitrary read/write operations through a specially crafted HTML page. The vulnerability has a CVSS score of 6.5, indicating a network-based attack with low complexity and potential for information disclosure and integrity impact. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 141.0.7390.54CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 141.0.7390.54, < 141.0.7390.54CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.