CVE-2025-13992Improper Protection of Physical Side Channels in Google Chrome

Severity
4.7MEDIUMNVD
EPSS
0.0%
top 88.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 3

Description

Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5google/chrome139.0.7258.66139.0.7258.66
NVDgoogle/chrome< 139.0.7258.66
Debianchromium/chromium< 139.0.7258.66-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-cfr8-3v62-gpqj: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 1392025-12-03
CVEList
CVE-2025-13992: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 1392025-12-03
OSV
CVE-2025-13992: Side-channel information leakage in Navigation and Loading in Google Chrome prior to 1392025-12-03

📋Vendor Advisories

2
Red Hat
chromium-browser: Side-channel information leakage in Navigation and Loading2025-12-03
Debian
CVE-2025-13992: chromium - Side-channel information leakage in Navigation and Loading in Google Chrome prio...2025
CVE-2025-13992 — Google Chrome vulnerability | cvebase