CVE-2025-4664Disclosure(google / chrome)

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-19: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-09-22: 1Technical Details · 2026-04-19: 104-1909-22
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-191
Disclosure1
2026-09-221
PoC1
Full discourse2 posts
  • Muqsit 𝕏@mqst_
    PoC

    🥬 CVE-2025-4664: Exploiting a Chrome 0day to Leak Session Tokens Blog: https://amalmurali.me/posts/cve-2025-4664/ Author: @amalmurali47 https://t.co/3xYXiUYgES

    Post summary

    The tweet links to a blog post detailing exploitation of CVE-2025-4664 in Chrome, presenting it as a PoC for leaking session tokens, making 'PoC' the primary classification.

    114094465.1K
    13.3K followersView on X
  • MetaKing@techpediax
    Disclosure

    🚨 BREAKING: Google Chrome Zero-Day Exploit 2026 — CVE-2025-4664 CVSS Score: 9.8/10 (CRITICAL) Affected: 3.2 BILLION users worldwide Are you safe? Check your Chrome version NOW 👇 https://techpediax.com/google-chrome-zero-day-exploit-2026/ #ChromeZeroDay #CyberSecurity #CVE20254664 #CERTIn #InfoSec https://t.co/s9UzSUfPUE

    Post summary

    A tweet that announces the discovery of CVE‑2025‑4664, a critical zero‑day for Chrome, but provides no evidence of active use, exploitation code, or remediation.

    02021445
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more