CVE-2025-13097: Inappropriate implementation in DevTools
Published Mar 13, 2025
·Updated
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Credit
Alesandro Ortiz
Affected Software
7 affected componentsFixes available
Google Chrome<136.0.7103.59
All of the following
Google Chrome<136.0.7103.59
Linux Linux kernel
All of the following
Google Chrome<136.0.7103.48
Any of the following
Apple macOS
Microsoft Windows
Google Chrome<136.0.7103.59
136.0.7103.59
Event History
Mar 13, 2025
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Nov 14, 2025
CVE Published
via MITRE·02:29 AM
Data Sourced
via MITRE·02:29 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-13097?
The severity of CVE-2025-13097 is classified as Medium by Chromium security standards.
2
How do I fix CVE-2025-13097?
To fix CVE-2025-13097, you should update Google Chrome to version 136.0.7103.59 or later.
3
What can an attacker potentially do with CVE-2025-13097?
An attacker can potentially perform a sandbox escape via a crafted HTML page due to the vulnerability in CVE-2025-13097.
4
Which versions of Google Chrome are affected by CVE-2025-13097?
CVE-2025-13097 affects Google Chrome versions prior to 136.0.7103.59.
5
Is CVE-2025-13097 a local or remote vulnerability?
CVE-2025-13097 is classified as a remote vulnerability.