CVE-2025-4613: Google Web Designer

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template

Affected products

  • Google Web Designer: before 16.3.0.0407 (fixed in 16.3.0.0407)

Published 2025-06-12. Last modified 2026-06-17.