CVE-2025-6557: Insufficient data validation in DevTools
Chromium: CVE-2025-6557 Insufficient data validation in DevTools
Other sources
Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 138.0.7204.49 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 138.0.7204.49 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 138.0.7204.49
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6557?
CVE-2025-6557 has a severity rating of Low according to Chromium security metrics.
How do I fix CVE-2025-6557?
To mitigate CVE-2025-6557, upgrade Google Chrome to version 138.0.7204.49 or later.
What does CVE-2025-6557 affect?
CVE-2025-6557 affects Google Chrome on Windows prior to version 138.0.7204.49.
What is the nature of CVE-2025-6557?
CVE-2025-6557 involves insufficient data validation in DevTools allowing execution of arbitrary code.
Can a user be exploited through CVE-2025-6557?
Yes, a remote attacker can exploit CVE-2025-6557 if a user engages in specific UI gestures on a crafted HTML page.