CVE-2025-13631: Inappropriate implementation in Google Updater
Chromium: CVE-2025-13631 Inappropriate implementation in Google Updater
Other sources
Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform privilege escalation via a crafted file. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 143.0.7499.40 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 143.0.7499.41
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13631?
CVE-2025-13631 has a security severity rating of High.
How do I fix CVE-2025-13631?
To fix CVE-2025-13631, update Google Chrome to version 143.0.7499.41 or later.
What type of vulnerability is CVE-2025-13631?
CVE-2025-13631 is a privilege escalation vulnerability in Google Updater within Google Chrome.
Which versions of Google Chrome are affected by CVE-2025-13631?
CVE-2025-13631 affects Google Chrome versions prior to 143.0.7499.41.
Can CVE-2025-13631 be exploited remotely?
Yes, CVE-2025-13631 allows a remote attacker to exploit the vulnerability via a crafted file.