CVE-2025-12726: Inappropriate implementation in Views
Chromium: CVE-2025-12726 Inappropriate implementation in Views.
Other sources
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 142.0.7444.134 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 142.0.7444.137
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12726?
The severity of CVE-2025-12726 is classified as medium, indicating a potential risk to affected systems.
How do I fix CVE-2025-12726?
To fix CVE-2025-12726, users should update Google Chrome to version 142.0.7444.134 or newer, or update Microsoft Edge to the latest available version.
Which software is affected by CVE-2025-12726?
CVE-2025-12726 affects Google Chrome versions prior to 142.0.7444.134 and Microsoft Edge (Chromium-based) that relies on the Chromium engine.
What type of vulnerability is CVE-2025-12726?
CVE-2025-12726 is categorized as an inappropriate implementation vulnerability in the Views component of Chromium.
Who reported CVE-2025-12726?
CVE-2025-12726 was reported by the Google Chrome team and affects Google Chrome and Microsoft Edge (Chromium-based) due to their shared engine.