CVE-2025-4609 — Incorrect Permission Assignment in Google Chrome
Severity
9.6CRITICALNVD
EPSS
0.0%
top 92.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Description
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0
Affected Packages3 packages
🔴Vulnerability Details
3OSV▶
CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136↗2025-08-22
GHSA▶
GHSA-c8mh-mfhv-j36q: Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136↗2025-08-22
CVEList▶
CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136↗2025-08-22