Policy Bypass in Google Chrome Extensions
CVE-2025-12436

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
10 November 2025

What is CVE-2025-12436?

A policy bypass vulnerability in Google Chrome allows attackers to exploit malicious extensions to gain access to sensitive information stored in process memory. Users who inadvertently install these harmful extensions may expose their data without realizing it. This issue emphasizes the importance of scrutinizing extension permissions and maintaining updated software to mitigate such risks.

Affected Version(s)

Chrome 142.0.7444.59

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12436 : Policy Bypass in Google Chrome Extensions