{"id":1085,"date":"2025-05-16T11:13:19","date_gmt":"2025-05-16T08:13:19","guid":{"rendered":"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/"},"modified":"2025-05-16T11:13:19","modified_gmt":"2025-05-16T08:13:19","slug":"cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/","title":{"rendered":"CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation"},"content":{"rendered":"<p>On May 15, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to U.S. federal agencies regarding a significant vulnerability in the Chrome web browser, designated as CVE-2025-4664. The flaw poses a high risk due to its active exploitation in the wild. Researchers from Solidlab, led by Vsevolod Kokorin, initially discovered the weakness and published detailed technical information on May 5. Consequently, Google released security updates to mitigate the threat on May 14.<\/p>\n<p>The vulnerability stems from inadequate policy enforcement within Chrome&#8217;s Loader component. Its successful exploitation could allow remote attackers to access cross-origin data through specially crafted HTML pages. Kokorin highlighted that while Chrome handles Link headers differently from other browsers by resolving them in subresource requests, this creates vulnerabilities. Specifically, if an attacker sets an unsafe referrer-policy in the Link header, they can proceed to capture sensitive query parameters embedded within URLs.<\/p>\n<p>These query parameters can contain essential data that, particularly in OAuth workflows, could lead to account takeovers. Kokorin remarked that developers often overlook the risks posed by third-party resources, which could inadvertently expose sensitive information when exploited through images or other means.<\/p>\n<p>While Google has yet to confirm any prior abuse of the vulnerability, the company stressed its potential for exploitation, noted by its inclusion in the advisory addressing public exploit availability. CISA subsequently categorized CVE-2025-4664 as an actively exploited vulnerability, adding it to its Known Exploited Vulnerabilities catalog. This catalog enumerates flaws that are currently being utilized in cyberattacks.<\/p>\n<p>In compliance with the November 2021 Binding Operational Directive (BOD) 22-01, U.S. Federal Civilian Executive Branch agencies are mandated to apply patches for their Chrome installations within a three-week deadline, prompting necessary actions by May 7. Although this directive primarily pertains to federal entities, network defenders in all sectors are strongly encouraged to prioritize this patching to safeguard against potential breaches.<\/p>\n<p>CISA has emphasized the critical nature of patching such vulnerabilities, which typically serve as common attack vectors for malicious cyber actors, posing significant threats to federal infrastructure.<\/p>\n<p>This incident marks the second instance this year where Google patched an actively exploited zero-day vulnerability in Chrome, following the identification of another high-risk zero-day, CVE-2025-2783. This particular flaw was exploited in targeted cyber-espionage efforts against Russian governmental organizations, media outlets, and educational institutions. Researchers from Kaspersky discovered that attackers leveraged the CVE-2025-2783 exploit to circumvent Chrome\u2019s sandbox protections and deploy malware on affected systems.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On May 15, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to U.S. federal agencies regarding a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1086,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[382,384,383],"class_list":["post-1085","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-browser-vulnerability","tag-html-exploitation","tag-referrer-policy"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation\" \/>\n<meta property=\"og:description\" content=\"On May 15, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to U.S. federal agencies regarding a...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-16T08:13:19+00:00\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"\u062f\u0642\u064a\u0642\u062a\u0627\u0646\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/\",\"url\":\"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/\",\"name\":\"CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation.webp\",\"datePublished\":\"2025-05-16T08:13:19+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/#primaryimage\",\"url\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation.webp\",\"contentUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation.webp\",\"width\":1792,\"height\":1024,\"caption\":\"CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation[:] - Trustcrypt","og_description":"On May 15, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) issued a warning to U.S. federal agencies regarding a...","og_url":"https:\/\/trustcrypt.com\/ar\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/","og_site_name":"Trustcrypt","article_published_time":"2025-05-16T08:13:19+00:00","author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"\u062f\u0642\u064a\u0642\u062a\u0627\u0646"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/","url":"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/","name":"CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/#primaryimage"},"image":{"@id":"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/#primaryimage"},"thumbnailUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation.webp","datePublished":"2025-05-16T08:13:19+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation\/#primaryimage","url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation.webp","contentUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/cisa-identifies-recently-mitigated-chrome-vulnerability-as-under-active-exploitation.webp","width":1792,"height":1024,"caption":"CISA Identifies Recently Mitigated Chrome Vulnerability as Under Active Exploitation"},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1085","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=1085"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1085\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media\/1086"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=1085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=1085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=1085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}