CVE-2025-13637
MEDIUMDescription
Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass download protections via a crafted HTML page. (Chromium security severity: Low)
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| chrome | |
| linux | linux_kernel |
| chrome | |
| apple | macos |
| microsoft | windows |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-13637? +
How severe is CVE-2025-13637? +
What products are affected by CVE-2025-13637? +
How do I check if I'm vulnerable to CVE-2025-13637? +
Related Vulnerabilities
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
LinkedIn Mobile Application for Android version 4.1.1087.2 fails to update link preview metadata (image, title, description) when a user replaces …
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability