cbcvebase.
CVE-2025-4096
published 2025-05-05

CVE-2025-4096: Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.47%
37.7th percentile
Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected

20 ranges
VendorProductVersion rangeFixed in
chromiumchromium>= 0 < 136.0.7103.59-2~deb12u2136.0.7103.59-2~deb12u2
chromiumchromium>= 0 < 136.0.7103.59-2136.0.7103.59-2
chromiumchromium>= 0 < 136.0.7103.59-2136.0.7103.59-2
debianchromium< chromium 136.0.7103.59-2~deb12u2 (bookworm)chromium 136.0.7103.59-2~deb12u2 (bookworm)
ericssoncodechecker>= 0 < 6.26.26.26.2
googlechrome< 136.0.7103.59136.0.7103.59
googlechrome>= 136.0.7103.59 < 136.0.7103.59136.0.7103.59
googlechrome_chrome
linuxlinux_kernel>= 0 < 6.1.1596.1.159
linuxlinux_kernel>= 3.19.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.13.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.13.0 < 6.14.96.14.9
linuxlinux_kernel>= 6.17.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1146.6.114
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
linuxlinux_kernel>= 6.7.0 < 6.12.316.12.31
msrccbl2_dnsmasq_2.89-2_on_cbl_mariner_2.0
msrccm1_dnsmasq_2.85-2_on_cbl_mariner_1.0
msrcmicrosoft_edge
paloaltoprisma_browser

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.