← back
CVE-2025-11207mediumCWE-125CWE-1300

CVE-2025-11207

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.2%
exploitation probability
0.2%top 84% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Google Chrome's storage system allows attackers to read or write data through a specially crafted webpage, potentially exposing sensitive information stored by the browser.

Technical detail

Side-channel vulnerability in Chrome's Storage API (CWE-125: Out-of-bounds Read; CWE-1300: Information Exposure) enables remote code execution of arbitrary read/write operations when a user visits a malicious HTML page. Exploitation requires user interaction (visiting crafted site) but can leak data from browser storage or other sensitive locations.

Summary generated and translated by AI from the official description.
Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
Google · Chrome