CVE-2025-12910: Inappropriate implementation in Passkeys
Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.0.7339.80
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12910?
The severity of CVE-2025-12910 is classified as Low according to Chromium security ratings.
How do I fix CVE-2025-12910?
To fix CVE-2025-12910, update Google Chrome to version 140.0.7339.80 or later.
What type of information can be exposed due to CVE-2025-12910?
CVE-2025-12910 may allow a local attacker to obtain potentially sensitive information via debug logs.
Which versions of Google Chrome are affected by CVE-2025-12910?
Google Chrome versions prior to 140.0.7339.80 are affected by CVE-2025-12910.
Who is vulnerable to CVE-2025-12910?
Users of Google Chrome before version 140.0.7339.80 may be vulnerable to CVE-2025-12910.