CVE-2025-4096: Heap buffer overflow in HTML
Chromium: CVE-2025-4096 Heap buffer overflow in HTML
Other sources
Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4096?
CVE-2025-4096 is considered a high severity vulnerability affecting Chromium-based browsers.
How do I fix CVE-2025-4096?
To fix CVE-2025-4096, update Google Chrome to version 136.0.7103.59 or Microsoft Edge to version 136.0.3240.50 or higher.
Which browsers are affected by CVE-2025-4096?
CVE-2025-4096 affects Google Chrome and Microsoft Edge (Chromium-based) browsers.
What kind of vulnerability is CVE-2025-4096?
CVE-2025-4096 is categorized as a security vulnerability related to improper input validation.
Can I check for updates to mitigate CVE-2025-4096?
Yes, you can check for updates directly within Google Chrome or Microsoft Edge through the browser settings.