CVE-2025-4050: Out of bounds memory access in DevTools
Chromium: CVE-2025-4050 Out of bounds memory access in DevTools
Other sources
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4050?
CVE-2025-4050 is classified as a high-severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2025-4050?
To fix CVE-2025-4050, update Google Chrome to version 136.0.7103.59 or later, or update Microsoft Edge to the latest version.
Which versions of software are affected by CVE-2025-4050?
CVE-2025-4050 affects Google Chrome versions prior to 136.0.7103.59 and Microsoft Edge versions prior to 136.0.3240.50.
Is CVE-2025-4050 a known issue for Microsoft Edge?
Yes, CVE-2025-4050 impacts Microsoft Edge, particularly its Chromium-based versions.
What type of vulnerability is CVE-2025-4050?
CVE-2025-4050 is a heap buffer overflow vulnerability.