CVE-2025-4609: Google Chrome

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Affected products

  • Google Chrome: before 136.0.7103.113 (fixed in 136.0.7103.113)

Published 2025-08-22. Last modified 2026-06-17.