Tag: Chrome Vulnerability

New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy
News

New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

Google fixed four security flaws in its Chrome browser on Wednesday, including one for which it claimed there was an exploit in the wild. CVE-2025-4664, a high-severity vulnerability with a CVSS score of 4.3, has been described as an instance of inadequate policy enforcement in a component known as Loader. A summary of the vulnerability states that "a remote attacker was able to leak cross-origin data via a crafted HTML page due to inadequate policy enforcement in Loader in Google Chrome prior to 136.0.7103.113." The tech giant acknowledged that an attack for CVE-2025-4664 is in the wild and gave credit to security researcher Vsevolod Kokorin (@slonser_) for describing the X vulnerability on May 5, 2025. Chrome resolves the Link header on sub-resource requests, in contrast to ...
Google Issues Patch for New Chrome Vulnerability Update Now
News

Google Issues Patch for New Chrome Vulnerability Update Now

On Monday, Google released security upgrades to fix a critical bug in its Chrome web browser that the company claimed is already being actively used in the wild. The vulnerability, identified as CVE-2023-3079, is a type misunderstanding fault in the V8 JavaScript engine. On June 1, 2023, Clement Lecigne of Google's Threat Analysis Group (TAG) is credited for reporting the problem. "Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page," according to the National Vulnerability Database (NVD) of NIST read more Google Issues Patch for New Chrome Vulnerability Update Now. Stay one step ahead of cyber threats with ReconBee.com. Explore our comprehensive coverage of recent cyber attacks, cy...