CVE-2025-4609: Incorrect handle provided in unspecified circumstances in Mojo
Chromium: CVE-2025-4609 Incorrect handle provided in unspecified circumstances in Mojo
Other sources
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4609?
CVE-2025-4609 is classified as a high-severity vulnerability affecting Chrome and Chromium-based browsers.
How do I fix CVE-2025-4609?
To remediate CVE-2025-4609, update Google Chrome to version 136.0.7103.113 or later, and ensure Microsoft Edge is updated as well.
Which versions are affected by CVE-2025-4609?
CVE-2025-4609 affects Google Chrome versions prior to 136.0.7103.113 and Microsoft Edge versions before 136.0.3240.76.
Who is the vendor for CVE-2025-4609?
CVE-2025-4609 was reported by the Google team and affects products from both Google and Microsoft.
Is CVE-2025-4609 being actively exploited?
As of the latest information, there are indications that CVE-2025-4609 may be actively exploited in the wild.