CVE-2025-13992: previousversion of these notes did not include the following security fixes which were included in the release:[TBD][40095391] Medium : Side-channel information leakage in Navigation and Loading
Published Jun 13, 2019
·Updated
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Credit
Ivan Fratric(Google Project Zero)
Affected Software
5 affected componentsFixes available
Google Chrome<139.0.7258.66
139.0.7258.66
All of the following
Google Chrome<139.0.7258.66
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Jun 13, 2019
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Dec 3, 2025
CVE Published
via MITRE·07:09 PM
Data Sourced
via MITRE·07:09 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-13992?
The severity of CVE-2025-13992 is classified as Medium according to Chromium security standards.
2
How do I fix CVE-2025-13992?
To fix CVE-2025-13992, update Google Chrome to version 139.0.7258.66 or later.
3
What type of vulnerability is CVE-2025-13992?
CVE-2025-13992 is a side-channel information leakage vulnerability in Navigation and Loading in Google Chrome.
4
Can CVE-2025-13992 be exploited by remote attackers?
Yes, a remote attacker can exploit CVE-2025-13992 by using a crafted HTML page to bypass site isolation.
5
Is CVE-2025-13992 present in all versions of Google Chrome?
CVE-2025-13992 is present in Google Chrome versions prior to 139.0.7258.66.