CVE-2025-4609 is a critical vulnerability affecting Google Chrome on Windows, specifically versions prior to 136.0.7103.113. This flaw, stemming from an incorrect handle in Mojo, allows a remote attacker to potentially achieve a sandbox escape via a malicious file. With a CVSS score of 9.6 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, enabling high impact on confidentiality, integrity, and availability. While not yet added to CISA's KEV catalog, there is significant community discussion and media coverage, including reports of a security researcher receiving a substantial bounty for its discovery, indicating active interest and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 136.0.7103.113CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 136.0.7103.113, < 136.0.7103.113CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.