Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » News » Security » Chrome vulnerability allowing account takeover fixed
2 min Security

Chrome vulnerability allowing account takeover fixed

Berry ZwetsMay 15, 2025 3:54 pmMay 15, 2025 3:54 pm
Chrome vulnerability allowing account takeover fixed

Google has released an emergency update for the Chrome browser to fix a serious security vulnerability. This vulnerability allowed someone to completely take over accounts.

According to Google, the bug, known as CVE-2025-4664, already has a publicly available exploit, which usually indicates active abuse. Users are advised to update their browser to the latest version as soon as possible.

Security researcher Vsevolod Kokorin of Solidlab discovered and analyzed the vulnerability. The problem lies in Chrome’s Loader component, which allows malicious actors to leak data between different sources via specially designed HTML pages.

How the vulnerability works

“Unlike other browsers, Chrome resolves the Link header on subresource requests. But what’s the problem? The issue is that the Link header can set a referrer-policy. We can specify unsafe-url and capture the full query parameters,” Kokorin explains.

According to the researcher, query parameters can contain sensitive information, such as data used in OAuth authentication flows. This can lead to complete account takeover. “Developers rarely consider the possibility of stealing query parameters via an image from a 3rd-party resource,” he adds.

Google has fixed the issue for Chrome users in the Stable Desktop channel. The updated versions (136.0.7103.113 for Windows/Linux and 136.0.7103.114 for macOS) are being rolled out to all users.

Tip: Google patches critical vulnerability in Chrome

Tags:

account takeover / browser security / Google Chrome / security vulnerability

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Stay tuned, subscribe!

Nieuwsbrieven*

Related

Critical kernel vulnerability affects a wide range of Linux distributions

Adobe patches vulnerability that steals data via PDFs

NinjaOne launches Vulnerability Management for detection and remediation

Cisco details further vulnerabilities in Catalyst SD-WAN Manager

Editor picks

ASML signs new customer: what does India’s Tata Electronics do?

ASML will supply machines to Tata Electronics for India’s first chi...

On Anti-Ransomware Day, some good news arrives for cyber defenders

A surprisingly positive development: ransomware is on the decline. Th...

AI chipmaker Cerebras jumps 68% on IPO, market cap now sits at 95B

Market value soars to $95 billion

AWS invests massively in AI: can it stay ahead of the pack?

AWS is still the biggest hyperscaler, even though the gap with Micros...

Techzine.tv

groundcover uses eBPF and AI agents to modernize observability

groundcover uses eBPF and AI agents to modernize observability

Your network isn't ready for AI: Here's what needs to change

Your network isn't ready for AI: Here's what needs to change

Cisco doubled down on compute for the AI and edge era

Cisco doubled down on compute for the AI and edge era

How to migrate from Redis to Valkey with zero downtime

How to migrate from Redis to Valkey with zero downtime

Read more on Security

Iran threatens to impose fees on subsea cables in the Strait of Hormuz

Iran threatens to impose fees on subsea cables in the Strait of Hormuz

The Iranian government has announced that it intends to impose tolls on undersea internet cables in the Strai...

Erik van Klinken 10 hours ago
TeamPCP compromises Python libraries via supply chain attack

TeamPCP compromises Python libraries via supply chain attack

The hacker group TeamPCP uploaded two malicious versions of the popular Python library LiteLLM to PyPI. Using...

Berry Zwets 3 hours ago
Akamai acquires LayerX for browser-native AI-era workforce controls
Top story

Akamai acquires LayerX for browser-native AI-era workforce controls

Akamai is a cloud cybersecurity company that dedicates itself to the provision of what it calls “superior t...

Adrian Bridgwater 11 hours ago
It’s raining Linux vulnerabilities: what’s going on?
Top story

It’s raining Linux vulnerabilities: what’s going on?

In recent weeks, alarm bells have been ringing repeatedly over critical vulnerabilities in the Linux kernel. ...

Erik van Klinken May 15, 2026

Expert Talks

Five tips for embracing continuous deployment as a DevOps mindset

Five tips for embracing continuous deployment as a DevOps mindset

Continuous deployment offers quicker releases and better software, bu...

The only thing constant in technology is change, except for unrealistic hopefulness

The only thing constant in technology is change, except for unrealistic hopefulness

If anyone was ever forced to pick the tritest phrase in the world, it...

mnemonic opens Dutch Security Operations Centre (SOC) and relocates to new office in Utrecht

The new SOC in the Netherlands further strengthens mnemonic’s regio...

AI governance: the invisible prerequisite for success

When AI never gets past the demo

Tech calendar

Infosecurity Europe

June 2, 2026 London

.NEXT On Tour Amsterdam

June 9, 2026 Amsterdam

Oxygenate

June 11, 2026 Hilversum

VivaTech

June 17, 2026 Paris Expo Porte de Versailles 1 Place de la Porte de Versailles Pavillon 7 F-75015 Paris France

GITEX AI EUROPE 2026

June 30, 2026 Messe Berlin Exhibition Center, South Entrance

GOTO Copenhagen 2026

September 28, 2026 TAP1, Raffinaderivej 10, 2300 København S, Denmark

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2026 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement