CVE-2025-13992
published 2025-12-03CVE-2025-13992: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a…
PriorityP421medium4.7CVSS 3.1
AVNACLPRNUIRSCCLINAN
EPSS
0.17%
6.4th percentile
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 139.0.7258.66-1~deb12u1 | 139.0.7258.66-1~deb12u1 |
| chromium | chromium | >= 0 < 139.0.7258.127-1~deb13u1 | 139.0.7258.127-1~deb13u1 |
| chromium | chromium | >= 0 < 139.0.7258.66-1 | 139.0.7258.66-1 |
| debian | chromium | < chromium 139.0.7258.66-1~deb12u1 (bookworm) | chromium 139.0.7258.66-1~deb12u1 (bookworm) |
| chrome | < 139.0.7258.66 | 139.0.7258.66 | |
| chrome | >= 139.0.7258.66 < 139.0.7258.66 | 139.0.7258.66 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cfr8-3v62-gpqj: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139
ghsa_unreviewed·2025-12-03
CVE-2025-13992 [MEDIUM] CWE-1300 GHSA-cfr8-3v62-gpqj: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2025-13992: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139
osv·2025-12-03·CVSS 4.7
CVE-2025-13992 [MEDIUM] CVE-2025-13992: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Red Hat
chromium-browser: Side-channel information leakage in Navigation and Loading
vendor_redhat·2025-12-03·CVSS 4.7
CVE-2025-13992 [MEDIUM] CWE-385 chromium-browser: Side-channel information leakage in Navigation and Loading
chromium-browser: Side-channel information leakage in Navigation and Loading
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
A flaw was found in Google Chrome. This vulnerability allows a remote attacker to bypass site isolation via side-channel information leakage in Navigation and Loading through a crafted HyperText Markup Language (HTML) page.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Debian
CVE-2025-13992: chromium - Side-channel information leakage in Navigation and Loading in Google Chrome prio...
vendor_debian·2025·CVSS 4.7
CVE-2025-13992 [MEDIUM] CVE-2025-13992: chromium - Side-channel information leakage in Navigation and Loading in Google Chrome prio...
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 139.0.7258.66-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.0.7258.66-1)
sid: resolved (fixed in 139.0.7258.66-1)
trixie: resolved (fixed in 139.0.7258.127-1~deb13u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-03
Published