Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5952-1 | chromium security update |
EUVD |
EUVD-2025-19071 | Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows |
|
| CPEs | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows |
Wed, 02 Jul 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome |
|
| CPEs | cpe:2.3:a:google:chrome:*:*:*:*:*:windows:*:* | |
| Vendors & Products |
Google
Google chrome |
Tue, 24 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1021 | |
| Metrics |
cvssV3_1
|
Tue, 24 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low) | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-02-26T17:50:25.618Z
Reserved: 2025-06-23T22:30:38.459Z
Link: CVE-2025-6557
Updated: 2025-06-24T20:41:06.511Z
Status : Analyzed
Published: 2025-06-24T20:15:27.333
Modified: 2025-07-15T18:26:56.320
Link: CVE-2025-6557
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:26Z
Debian DSA
EUVD