New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy
Google fixed four security flaws in its Chrome browser on Wednesday, including one for which it claimed there was an exploit in the wild.
CVE-2025-4664, a high-severity vulnerability with a CVSS score of 4.3, has been described as an instance of inadequate policy enforcement in a component known as Loader.
A summary of the vulnerability states that "a remote attacker was able to leak cross-origin data via a crafted HTML page due to inadequate policy enforcement in Loader in Google Chrome prior to 136.0.7103.113."
The tech giant acknowledged that an attack for CVE-2025-4664 is in the wild and gave credit to security researcher Vsevolod Kokorin (@slonser_) for describing the X vulnerability on May 5, 2025.
Chrome resolves the Link header on sub-resource requests, in contrast to ...


