CVE-2025-12445Authentication Bypass Using an Alternate Path or Channel in Google Chrome

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 96.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateNov 12

Description

Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages4 packages

CVEListV5google/chrome142.0.7444.59142.0.7444.59
NVDgoogle/chrome< 142.0.7444.59
Debianchromium/chromium< 142.0.7444.59-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-3x5x-62pf-8jpr: Policy bypass in Extensions in Google Chrome prior to 1422025-11-10
CVEList
CVE-2025-12445: Policy bypass in Extensions in Google Chrome prior to 1422025-11-10
OSV
CVE-2025-12445: Policy bypass in Extensions in Google Chrome prior to 1422025-11-10

📋Vendor Advisories

5
Palo Alto
PAN-SA-2025-0018 Chromium and Prisma Browser: Monthly Vulnerability Update (November 2025)2025-11-12
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-124452025-11-11
Red Hat
chromium-browser: Policy bypass in Extensions2025-11-10
Microsoft
Chromium: CVE-2025-12445 Policy bypass in Extensions2025-10-14
Debian
CVE-2025-12445: chromium - Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an a...2025
CVE-2025-12445 — Google Chrome vulnerability | cvebase