Inappropriate Implementation in App-Bound Encryption of Google Chrome
CVE-2025-12439

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
10 November 2025

What is CVE-2025-12439?

An inappropriate implementation in the App-Bound Encryption feature of Google Chrome on Windows prior to version 142.0.7444.59 could allow a local attacker to exploit this flaw. By utilizing a malicious file, the attacker could potentially gain access to sensitive information from the process memory, leading to serious privacy concerns. Ensuring that users are updated to the latest version of Chrome is crucial for mitigating this risk.

Affected Version(s)

Chrome 142.0.7444.59

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12439 : Inappropriate Implementation in App-Bound Encryption of Google Chrome