CVE-2025-4050 is an out-of-bounds memory access vulnerability in Google Chrome's DevTools, affecting versions prior to 136.0.7103.59. A remote attacker could exploit this by crafting an HTML page and convincing a user to perform specific UI gestures, potentially leading to heap corruption. With a CVSS score of 8.8 (High), this vulnerability has a low attack complexity and could result in high impacts to confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage are minimal, suggesting limited current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 136.0.7103.59CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 136.0.7103.59, < 136.0.7103.59CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.