CVE-2025-12436Missing Authentication for Critical Function in Google Chrome

Severity
5.9MEDIUMNVD
EPSS
0.0%
top 97.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateNov 12

Description

Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

CVEListV5google/chrome142.0.7444.59142.0.7444.59
NVDgoogle/chrome< 142.0.7444.59
Debianchromium/chromium< 142.0.7444.59-1~deb12u1+2

🔴Vulnerability Details

3
CVEList
CVE-2025-12436: Policy bypass in Extensions in Google Chrome prior to 1422025-11-10
OSV
CVE-2025-12436: Policy bypass in Extensions in Google Chrome prior to 1422025-11-10
GHSA
GHSA-j4j8-2vcc-42hj: Policy bypass in Extensions in Google Chrome prior to 1422025-11-10

📋Vendor Advisories

6
Palo Alto
PAN-SA-2025-0018 Chromium and Prisma Browser: Monthly Vulnerability Update (November 2025)2025-11-12
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-124362025-11-11
Red Hat
chromium-browser: Policy bypass in Extensions2025-11-10
Chrome
Stable Channel Update for Desktop: CVE-2025-124352025-10-28
Microsoft
Chromium: CVE-2025-12436 Policy bypass in Extensions2025-10-14
CVE-2025-12436 — Google Chrome vulnerability | cvebase