CVE-2025-4096 is a high-severity heap buffer overflow vulnerability in Google Chrome, affecting versions prior to 136.0.7103.59. This flaw allows a remote attacker to potentially corrupt memory and achieve high impact on confidentiality, integrity, and availability by enticing a user to visit a specially crafted HTML page. While the vulnerability has a high CVSS score of 8.8 and has garnered significant media attention, there is currently no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available. Its EPSS score is low, suggesting a minimal likelihood of exploitation in the wild at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 136.0.7103.59CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 136.0.7103.59, < 136.0.7103.59CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.