Insufficient Policy Enforcement in Loader for Google Chrome
CVE-2025-6556

6.5MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-6556?

A vulnerability in the Loader of Google Chrome prior to version 138.0.7204.49 allows remote attackers to bypass content security policies. This exploitation is achieved through specially crafted HTML pages, potentially compromising user data and security.

Affected Version(s)

Chrome 138.0.7204.49

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6556 : Insufficient Policy Enforcement in Loader for Google Chrome