Authentication Bypass by Spoofing
CVE-2025-13634
Summary
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to bypass mark of the web via a crafted HTML page.
- LOW
- LOCAL
- LOW
- UNCHANGED
- REQUIRED
- NONE
- LOW
- NONE
CWE-290 - Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
Advisory Timeline
- Published