CVE-2025-4052: Inappropriate implementation in DevTools
Chromium: CVE-2025-4052 Inappropriate implementation in DevTools
Other sources
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4052?
CVE-2025-4052 is classified as a high severity vulnerability affecting Google Chrome and Microsoft Edge.
How do I fix CVE-2025-4052?
To mitigate CVE-2025-4052, update Google Chrome to version 136.0.7103.59 or later, and Microsoft Edge to a version above 136.0.3240.50.
Which software is affected by CVE-2025-4052?
CVE-2025-4052 affects Google Chrome versions below 136.0.7103.59 and Microsoft Edge versions below 136.0.3240.50.
Is there a known exploit for CVE-2025-4052?
Details on exploitation are currently unclear, but high severity indicates a potential for significant impact if exploited.
When was CVE-2025-4052 disclosed?
CVE-2025-4052 was disclosed in April 2025.