Medium severity5.4NVD Advisory· Published Nov 14, 2025· Updated Jun 17, 2026
CVE-2025-13097
CVE-2025-13097
Description
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Affected products
6- osv-coords2 versions
< 136.0.7103.48-r0+ 1 more
- (no CPE)range: < 136.0.7103.48-r0
- (no CPE)range: < 136.0.7103.48-r0
Patches
Vulnerability mechanics
References
2- issues.chromium.org/issues/402791076nvdExploitIssue TrackingThird Party Advisory
- chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_29.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.