New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy

Google has released security updates to fix four vulnerabilities in Chrome, including one actively exploited in the wild. Users are advised to update their browsers to the latest versions to protect against potential data leaks and account compromises.
Affected: Google Chrome, Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi)

Keypoints

  • Google Chrome released updates to fix four security vulnerabilities.
  • A high-severity flaw (CVE-2025-4664) allows data leaks via the Loader component.
  • An exploit for CVE-2025-4664 is actively being used in the wild.
  • The vulnerability involves the mismanagement of the Link header which can leak sensitive query parameters.
  • Users should update their browsers to version 136.0.7103.113 or later to stay protected.

Read More: https://thehackernews.com/2025/05/new-chrome-vulnerability-enables-cross.html