Remote Code Execution Vulnerability in Google Web Designer for macOS and Linux
CVE-2025-1079

7.8HIGH

Key Information:

Vendor

Google

Vendor
CVE Published:
12 May 2025

What is CVE-2025-1079?

A remote code execution vulnerability exists in Google Web Designer's preview feature that could allow an attacker to exploit improper symbolic link resolution. Specifically, this issue affects users on macOS and Linux platforms, enabling unauthorized command execution on the client side. It is crucial for users of Google Web Designer to be aware of this vulnerability to mitigate potential security risks.

Affected Version(s)

Web Designer MacOS 0 < 16.2.0.0128

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bálint Magyar
.