CVE-2025-4664

Google Chromium: Loader Insufficient Policy Enforcement

As of , CVE-2025-4664 in Google Chromium is no longer on CISA's list of exploited vulnerabilities: CISA listed it on and removed it on .

CISA removed this entry from its list on 9 June 2025. CISA removes entries rarely: for example one added in error, or one whose fix caused a bigger problem. If CISA adds it back, this page will show it.

Exploited
CISA listed it on 15 May 2025 and removed it on 9 June 2025
US federal deadline
5 June 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.06Higher than 92% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: chromereleases.googleblog.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

Google Chromium contains an insufficient policy enforcement vulnerability that allows a remote attacker to leak cross-origin data via a crafted HTML page.

CISA's description

Timeline

  1. CISA added it to its list of exploited vulnerabilities.
  2. The US federal deadline to fix it.
  3. CISA removed it from its list.

Chromium: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-2441CSS Use-After-FreeGoogle ChromiumPatch this weekEPSS 0.550.55
CVE-2025-14174Out of Bounds Memory AccessGoogle ChromiumPatch soon0.22
CVE-2021-21166Race ConditionGoogle ChromiumPatch soon0.24
CVE-2021-37976Information DisclosureGoogle ChromiumPatch soon0.20
CVE-2025-6558ANGLE and GPU Improper Input ValidationGoogle ChromiumPatch soon0.09
CVE-2024-4671Visuals Use-After-FreeGoogle ChromiumPatch soon0.08

Read further