Chrome Cross-Origin Data Leak
- شناسه CVE: CVE-2025-4664
- شدت: بالا
- امتیاز CVSS: 7.5
- فروشنده/سازنده: Google
ChromeCross-OriginData LeakBrowser
A cross-origin data leak vulnerability in Google Chrome that allows a malicious website to read sensitive data from other origins visited by the user.
## Vulnerability Overview
This vulnerability in Chrome's Site Isolation implementation allows a malicious web page to bypass cross-origin restrictions and access data from other origins. The flaw exists in the Loader component's handling of Link response headers, where insufficient enforcement of cross-origin policies allows an attacker-controlled page to infer sensitive information.
## Technical Details
- **Type:** Cross-Origin Information Disclosure (CWE-200)
- **Root Cause:** Insufficient policy enforcement on the Link header in HTTP responses. An attacker can use the Link header with rel=prefetch to leak cross-origin URL parameters, including OAuth tokens, session IDs, and other sensitive query string data.
- **Attack Vector:** Victim visits a malicious web page
- **No User Interaction Beyond Visiting the Page Required**
## Impact
- Leak of OAuth authorization codes and tokens
- Theft of session identifiers from cross-origin URLs
- Potential account takeover via leaked authentication parameters
## Affected Versions
- Chrome < 131.0.6778.85
- All Chromium-based browsers (Edge, Brave, Opera) before equivalent patches
## Vulnerability Overview
This vulnerability in Chrome's Site Isolation implementation allows a malicious web page to bypass cross-origin restrictions and access data from other origins. The flaw exists in the Loader component's handling of Link response headers, where insufficient enforcement of cross-origin policies allows an attacker-controlled page to infer sensitive information.
## Technical Details
- **Type:** Cross-Origin Information Disclosure (CWE-200)
- **Root Cause:** Insufficient policy enforcement on the Link header in HTTP responses. An attacker can use the Link header with rel=prefetch to leak cross-origin URL parameters, including OAuth tokens, session IDs, and other sensitive query string data.
- **Attack Vector:** Victim visits a malicious web page
- **No User Interaction Beyond Visiting the Page Required**
## Impact
- Leak of OAuth authorization codes and tokens
- Theft of session identifiers from cross-origin URLs
- Potential account takeover via leaked authentication parameters
## Affected Versions
- Chrome < 131.0.6778.85
- All Chromium-based browsers (Edge, Brave, Opera) before equivalent patches
نرمافزارهای تحت تأثیر
- Google Chrome < 131.0.6778.85
- Chromium-based browsers