High severity8.8NVD Advisory· Published Nov 8, 2025· Updated Jun 17, 2026
CVE-2025-12907
CVE-2025-12907
Description
Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)
Affected products
5- osv-coords2 versions
< 140.0.7339.80-r0+ 1 more
- (no CPE)range: < 140.0.7339.80-r0
- (no CPE)range: < 140.0.7339.80-r0
Patches
Vulnerability mechanics
References
2- issues.chromium.org/issues/427367145nvdExploitIssue TrackingPatch
- chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.