CVE-2025-5281: Medium Inappropriate implementation in BFCache
Chromium: CVE-2025-5281 Inappropriate implementation in BFCache
Other sources
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5281?
The severity of CVE-2025-5281 is classified as Medium.
How do I fix CVE-2025-5281?
To fix CVE-2025-5281, update Google Chrome to version 137.0.7151.55 or later.
What does CVE-2025-5281 affect?
CVE-2025-5281 affects Google Chrome versions prior to 137.0.7151.55.
What type of vulnerability is CVE-2025-5281?
CVE-2025-5281 is an inappropriate implementation vulnerability in the BFCache feature.
Can CVE-2025-5281 lead to user data exposure?
Yes, CVE-2025-5281 could potentially allow a remote attacker to obtain user information via a crafted HTML page.