CVE-2025-4051: Insufficient data validation in DevTools
Chromium: CVE-2025-4051 Insufficient data validation in DevTools
Other sources
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4051?
CVE-2025-4051 is classified as a high severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2025-4051?
To fix CVE-2025-4051, update your Chrome browser to version 136.0.7103.59 or higher, or update Microsoft Edge to the latest version.
Which versions are affected by CVE-2025-4051?
CVE-2025-4051 affects Google Chrome versions prior to 136.0.7103.59 and Microsoft Edge versions prior to 136.0.3240.50.
Who is responsible for addressing CVE-2025-4051?
CVE-2025-4051 was addressed by Google for Chrome and has also been mitigated in Microsoft Edge since it is based on Chromium.
Is CVE-2025-4051 being exploited in the wild?
At this time, there is no public indication that CVE-2025-4051 is being actively exploited in the wild.