Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
                
            References
                    | Link | Resource | 
|---|---|
| https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_24.html | Vendor Advisory | 
| https://issues.chromium.org/issues/406631048 | Issue Tracking Permissions Required | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    15 Jul 2025, 18:26
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-24 20:15
Updated : 2025-07-15 18:26
NVD link : CVE-2025-6557
Mitre link : CVE-2025-6557
CVE.ORG link : CVE-2025-6557
JSON object : View
Products Affected
                - chrome
microsoft
- windows
CWE
                
                    
                        
                        CWE-1021
                        
            Improper Restriction of Rendered UI Layers or Frames
