Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
Metrics
Affected Vendors & Products
References
History
Tue, 06 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-838 | |
Metrics |
cvssV3_1
|
Mon, 05 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low) | |
References |
|

Status: PUBLISHED
Assigner: Chrome
Published: 2025-05-05T18:10:37.534Z
Updated: 2025-05-06T13:49:06.501Z
Reserved: 2025-04-28T20:34:01.730Z
Link: CVE-2025-4052

Updated: 2025-05-06T13:49:01.603Z

Status : Awaiting Analysis
Published: 2025-05-05T18:15:44.153
Modified: 2025-05-06T14:15:39.647
Link: CVE-2025-4052

No data.