Security Advisory

CVE-2025-12909

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-07 23:23:38
Last updated 2025-11-10 15:41:18
Assigner Chrome
CVSS score not scored
State PUBLISHED

Description

Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low)