CVE-2025-8881
published 2025-08-13CVE-2025-8881: Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.24%
15.2th percentile
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 139.0.7258.127-1~deb12u1 | 139.0.7258.127-1~deb12u1 |
| chromium | chromium | >= 0 < 139.0.7258.127-1~deb13u1 | 139.0.7258.127-1~deb13u1 |
| chromium | chromium | >= 0 < 139.0.7258.127-1 | 139.0.7258.127-1 |
| debian | chromium | < chromium 139.0.7258.127-1~deb12u1 (bookworm) | chromium 139.0.7258.127-1~deb12u1 (bookworm) |
| chrome | < 139.0.7258.127 | 139.0.7258.127 | |
| chrome | >= 139.0.7258.127 < 139.0.7258.127 | 139.0.7258.127 | |
| chrome_chrome | — | — | |
| linux | linux_kernel | >= 0 < 5.10.248 | 5.10.248 |
| linux | linux_kernel | >= 5.11.0 < 5.15.198 | 5.15.198 |
| linux | linux_kernel | >= 5.16.0 < 6.1.160 | 6.1.160 |
| linux | linux_kernel | >= 6.0.0 < 6.6.121 | 6.6.121 |
| linux | linux_kernel | >= 6.14.0 < 6.17.8 | 6.17.8 |
| linux | linux_kernel | >= 6.2.0 < 6.12.64 | 6.12.64 |
| linux | linux_kernel | >= 6.7.0 < 6.18.3 | 6.18.3 |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: NFSD: NFSv4 file creation neglects setting ACL
vendor_redhat·2026-01-13·CVSS 5.5
CVE-2025-68803 [MEDIUM] CWE-358 kernel: NFSD: NFSv4 file creation neglects setting ACL
kernel: NFSD: NFSv4 file creation neglects setting ACL
In the Linux kernel, the following vulnerability has been resolved:
NFSD: NFSv4 file creation neglects setting ACL
An NFSv4 client that sets an ACL with a named principal during file
creation retrieves the ACL afterwards, and finds that it is only a
default ACL (based on the mode bits) and not the ACL that was
requested during file creation. This violates RFC 8881 section
6.4.1.3: "the ACL attribute is set as given".
The issue occurs in nfsd_create_setattr(), which calls
nfsd_attrs_valid() to determine whether to call nfsd_setattr().
However, nfsd_attrs_valid() checks only for iattr changes and
security labels, but not POSIX ACLs. When only an ACL is present,
the function returns false, nfsd_setattr() is skipped, and the
POSIX ACL is
Red Hat
kernel: NFSD: Define actions for the new time_deleg FATTR4 attributes
vendor_redhat·2025-12-08·CVSS 5.5
CVE-2025-40326 [MEDIUM] CWE-1287 kernel: NFSD: Define actions for the new time_deleg FATTR4 attributes
kernel: NFSD: Define actions for the new time_deleg FATTR4 attributes
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Define actions for the new time_deleg FATTR4 attributes
NFSv4 clients won't send legitimate GETATTR requests for these new
attributes because they are intended to be used only with CB_GETATTR
and SETATTR. But NFSD has to do something besides crashing if it
ever sees a GETATTR request that queries these attributes.
RFC 8881 Section 18.7.3 states:
> The server MUST return a value for each attribute that the client
> requests if the attribute is supported by the server for the
> target file system. If the server does not support a particular
> attribute on the target file system, then it MUST NOT return the
> attribute value and MUST NOT set the attr
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-8881
vendor_chrome·2025-09-26·CVSS 6.5
CVE-2025-8881 [MEDIUM] Long Term Support Channel Update for ChromeOS: CVE-2025-8881
Long Term Support Channel Update for ChromeOS
CVE-2025-8881
Microsoft
Chromium: CVE-2025-8881 Inappropriate implementation in File Picker
vendor_msrc·2025-08-12·CVSS 6.5
CVE-2025-8881 [MEDIUM] Chromium: CVE-2025-8881 Inappropriate implementation in File Picker
Chromium: CVE-2025-8881 Inappropriate implementation in File Picker
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
139.0.3405.102
8/15/2025
139.0.7258.127/.128
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the versi
Debian
CVE-2025-8881: chromium - Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258...
vendor_debian·2025·CVSS 6.5
CVE-2025-8881 [MEDIUM] CVE-2025-8881: chromium - Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258...
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 139.0.7258.127-1~deb12u1)
bullseye: open
forky: resolved (fixed in 139.0.7258.127-1)
sid: resolved (fixed in 139.0.7258.127-1)
trixie: resolved (fixed in 139.0.7258.127-1~deb13u1)
OSV
NFSD: NFSv4 file creation neglects setting ACL
osv·2026-01-13
CVE-2025-68803 NFSD: NFSv4 file creation neglects setting ACL
NFSD: NFSv4 file creation neglects setting ACL
In the Linux kernel, the following vulnerability has been resolved:
NFSD: NFSv4 file creation neglects setting ACL
An NFSv4 client that sets an ACL with a named principal during file
creation retrieves the ACL afterwards, and finds that it is only a
default ACL (based on the mode bits) and not the ACL that was
requested during file creation. This violates RFC 8881 section
6.4.1.3: "the ACL attribute is set as given".
The issue occurs in nfsd_create_setattr(), which calls
nfsd_attrs_valid() to determine whether to call nfsd_setattr().
However, nfsd_attrs_valid() checks only for iattr changes and
security labels, but not POSIX ACLs. When only an ACL is present,
the function returns false, nfsd_setattr() is skipped, and the
POSIX ACL is never
OSV
NFSD: Define actions for the new time_deleg FATTR4 attributes
osv·2025-12-08
CVE-2025-40326 NFSD: Define actions for the new time_deleg FATTR4 attributes
NFSD: Define actions for the new time_deleg FATTR4 attributes
In the Linux kernel, the following vulnerability has been resolved:
NFSD: Define actions for the new time_deleg FATTR4 attributes
NFSv4 clients won't send legitimate GETATTR requests for these new
attributes because they are intended to be used only with CB_GETATTR
and SETATTR. But NFSD has to do something besides crashing if it
ever sees a GETATTR request that queries these attributes.
RFC 8881 Section 18.7.3 states:
> The server MUST return a value for each attribute that the client
> requests if the attribute is supported by the server for the
> target file system. If the server does not support a particular
> attribute on the target file system, then it MUST NOT return the
> attribute value and MUST NOT set the attribut
OSV
CVE-2025-8881: Inappropriate implementation in File Picker in Google Chrome prior to 139
osv·2025-08-13·CVSS 6.5
CVE-2025-8881 [MEDIUM] CVE-2025-8881: Inappropriate implementation in File Picker in Google Chrome prior to 139
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
GHSA
GHSA-c4fm-x36h-pwf6: Inappropriate implementation in File Picker in Google Chrome prior to 139
ghsa_unreviewed·2025-08-13
CVE-2025-8881 [MEDIUM] CWE-303 GHSA-c4fm-x36h-pwf6: Inappropriate implementation in File Picker in Google Chrome prior to 139
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2025-08-13
Published