Breaking
June 7, 2025

Billions of Chrome users at risk from new data-stealing browser vulnerability – here’s how to stay safe | usagoldmines.com


  • Google Chrome’s unique handling of referrer-policy creates a major loophole for silent data siphoning
  • CVE-2025-4664 proves even trusted browsers are not immune to catastrophic zero-day vulnerabilities
  • Cross-origin data is up for grabs if you haven’t updated Chrome or Chromium

A newly uncovered zero-day vulnerability which affects both Windows and Linux systems could put billions of Google Chrome and Chromium users at serious risk of data theft, experts have warned.

Researchers from Wazuh claim this flaw – tracked as CVE-2025-4664 – has already drawn urgent attention due to its ability to leak sensitive cross-origin data such as OAuth tokens and session identifiers without user interaction.

The flaw, identified in the Loader component of Chrome and Chromium browsers, relates to how these browsers process the Link HTTP header for sub-resource requests like images or scripts.

Chrome opening the door to data leaks

Unlike other mainstream browsers, Chrome honors the referrer-policy directive even on sub-resources.

This behavior allows a malicious site to inject a lax policy, such as unsafe-url, effectively leaking full URLs, including sensitive data, to third-party domains.

This kind of exploit bypasses conventional browser defenses and directly undermines common security assumptions in web infrastructure.

Wazuh claims it can detect and mitigate this flaw via its Wazuh Vulnerability Detection module, which uses data from its Cyber Threat Intelligence (CTI) service to monitor software versions and raise alerts when vulnerable packages are found.

In a lab environment set up using Wazuh OVA 4.12.0, security researchers demonstrated how endpoints running Windows 11 and Debian 11 could be scanned to identify whether they were running vulnerable versions of Chrome or Chromium.

As noted in Wazuh’s dashboard, users are instructed to add the query CVE-2025-4664 to quickly isolate impacted systems, with the module updating the vulnerability status from “Active” to “Solved” once mitigation steps are verified.

Google has issued an emergency patch to address the issue on Windows and Gentoo Linux systems. Users on these platforms are advised to update their browsers immediately.

For Chromium users on Debian 11, all versions up to 120.0.6099.224 remain vulnerable, and no updated package has yet been released. Users are encouraged to uninstall the browser until a patched version becomes available.

Despite these swift actions, the broader concern remains: how can users and enterprises reliably protect themselves against browser-based zero-day exploits?

Applying patches is essential, but relying solely on browser updates can leave significant gaps. For this reason, it is recommended to use endpoint protection platforms, along with malware protection and antivirus solutions, to stay safe.

These tools provide layered defenses that go beyond browser vulnerabilities, offering real-time detection and containment of exploit attempts.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Resident Evil Requiem officially announced and it's launching in February 2026 | usagoldmines.com

I can’t believe Deadpool is finally making his gaming return, and it’s as a hilarious Meta Quest 3 e...

Free-to-play PvP shooter Mecha Break officially launches for PC and Xbox Series X in July | usagold...

Street Fighter 6's Season 3 characters have been announced, thanks to wrestler Kenny Omega | usagol...

I Changed These Settings to Turn My iPhone Into a 'Dumbphone' and I'm Loving Using It Less Jake Pete...

Samsung’s AI-Powered Galaxy Watch 7 Is $200 Right Now Naima Karp | usagoldmines.com

How to Set Up and Start Using Your New Nintendo Switch 2 Michelle Ehrhardt | usagoldmines.com

Nvidia is planning to launch 11 DGX Spark and Station PCs with its partners: here they are | usagol...

Atomic Heart 2 officially announced at Summer Game Fest, along with an Atomic Heart multiplayer spin...

AI can write a hit song, but it can’t lift your soul or break your heart erichs211@gmail.com (Eric H...

Mafia: The Old Country gets a new story trailer and an official release date set for August | usago...

Dying Light: The Beast gets an official August release date at Summer Game Fest | usagoldmines.com

Anti-vaccine quack hired by RFK Jr. has started work at the health department Beth Mole | usagoldmin...

I Made Sense of Garmin’s Forerunner Models so You Don’t Have To Beth Skwarecki | usagoldmines.com

WWDC 2025 Preview: Apple's iOS 26 Design Overhaul, macOS Tahoe, and Much More Juli Clover | usagoldm...

NVMe HDDs are coming soon to a data center near you, but don't expect one to land in your PC before ...

Hideo Kojima debuts an exclusive new look at Death Stranding 2: On the Beach at Summer Game Fest | ...

Nintendo Switch 2 can make your old Switch games feel brand new again Andrew Cunningham | usagoldmin...

Anthropic releases custom AI chatbot for classified spy work Benj Edwards | usagoldmines.com

How to launch your browser in private mode with one click | usagoldmines.com

'Saved Info' Is Gemini's Hidden Superpower Eric Ravenscraft | usagoldmines.com

Four Things I Wish I Knew Before Training With the Garmin Forerunner 265 Beth Skwarecki | usagoldmin...

TikTok Getting Yet Another Ban Delay as Trump Fails to Reach Deal With China Juli Clover | usagoldmi...

iOS 26 Getting Custom AI-Generated Message Backgrounds, Generative Shortcuts and 'Mixmoji' Juli Clov...

This Android smartphone comes with a real QWERTY keyboard and a square screen, but will it be enough...

Ted Cruz bill: States that regulate AI will be cut out of $42B broadband fund Jon Brodkin | usagoldm...

Galaxy Watch Ultra, Watch 7, and Watch 6 Classic All Discounted – Some at 50% Off Kellen | usagoldmi...

Verizon Trick Gets You $20 Off Per Line for a Year Kellen | usagoldmines.com

The Utilities Questions No One Thinks to Ask Before Buying a House Jeff Somers | usagoldmines.com

Strava Is Publicly Sharing Data From Your Garmin Workouts Without Telling You Meredith Dietz | usago...

Over 4 billion user records leaked in "largest breach ever" - here's what you need to know | usagol...

Google upgrades Gemini 2.5 Pro's already formidable coding abilities erichs211@gmail.com (Eric Hal S...

Millions of low-cost Android devices turn home networks into crime platforms Dan Goodin | usagoldmin...

Ring has discontinued its least expensive smart lighting hub | usagoldmines.com

Microsoft fights USB-C chaos on Windows 11 laptops with new label | usagoldmines.com

I put my gaming PC in the wrong place, and learned it the hard way | usagoldmines.com

Upgrade to this 360Hz 1440p OLED gaming monitor for just $575 | usagoldmines.com

Gemini’s New Scheduled Actions Feature is Here and Sounds Awesome Kellen | usagoldmines.com

Best Apple Deals of the Week: Father's Day Deals Arrive With Great Sales From Anker, Sonos, Samsung,...

Lenovo quietly launched a PC based on AMD's fastest AI CPU but I don't think it will go on sale outs...

A Japanese lander crashed on the Moon after losing track of its location Stephen Clark | usagoldmine...

Simulations find ghostly whirls of dark matter trailing galaxy arms Ashley Balzer Vigil | usagoldmin...

Our first impressions after 48 hours with the Switch 2 Kyle Orland | usagoldmines.com

Stream for free: 8 best streaming services with free trials | usagoldmines.com

Take $400 off a Surface Laptop 15 with Snapdragon | usagoldmines.com

Apple Intelligence at WWDC 2025: Genmoji Upgrade Incoming Instead of Personalized Siri Joe Rossignol...

MacRumors Giveaway: Win an iPad Air and Rock Paper Pencil From Astropad Juli Clover | usagoldmines.c...

Apple TV+ Announces MLB Friday Night Baseball Schedule for July Joe Rossignol | usagoldmines.com

Sam Altman says AI chats should be as private as ‘talking to a lawyer or a doctor’, but OpenAI could...

What to expect from Apple’s Worldwide Developers Conference next week Andrew Cunningham | usagoldmin...

VR gaming isn’t dead yet! Valve’s Deckard headset is our last hope | usagoldmines.com

Microsoft begs/threatens Windows 10 users to upgrade, again | usagoldmines.com

Fastest VPN 2025: Top 5 fastest VPNs ranked | usagoldmines.com

Amazon Prime Day 2025: Everything you need to know | usagoldmines.com

iOS 26's Digital Glass Design: Home Screen Widgets, Camera, and More Joe Rossignol | usagoldmines.co...

Apple Reportedly Delays Two New iPhone Features Until iOS 27 Joe Rossignol | usagoldmines.com

86 million AT&T records leaked online - and this time they’re decrypted, so be on your guard ben...

If Apple redesigns the Phone App in iOS 26, I might just hang up lance.ulanoff@futurenet.com (Lance ...

GOP intensifies war against EVs and efficient cars Jonathan M. Gitlin | usagoldmines.com

Startup puts a logical qubit in a single piece of hardware John Timmer | usagoldmines.com

Cold case files: The medieval murder of a troublesome priest Jennifer Ouellette | usagoldmines.com

Google Chrome breaks ‘highest score ever’ on web speed benchmark | usagoldmines.com

How to launch your browser in private with one click | usagoldmines.com

Borderlands 2, the best Borderlands, is free on Steam right now | usagoldmines.com

iOS 26: New Messages and Phone App Features Leaked Ahead of WWDC Joe Rossignol | usagoldmines.com

Amazon Has AirPods Pro 2 at $169.99 and AirPods 4 at $99.99 Mitchel Broussard | usagoldmines.com

iOS 26's Rumored Games App Described in More Detail in New Report Joe Rossignol | usagoldmines.com

What WWDC 2025 will tell us about future Apple hardware philip.berne@futurenet.com (Philip Berne) | ...

FBI warns dangerous BADBOX 2.0 malware has hit over a million devices - here's how to stay safe | u...

The best monitors: 11 top picks for gaming, 4K, HDR, and more | usagoldmines.com

ChatGPT can now access Gmail, Outlook, and Google Drive in real time | usagoldmines.com

The Switch, Switch OLED, and Pro controller are all on sale right now | usagoldmines.com

Nvidia extends desktop GPU market share lead beyond 90% | usagoldmines.com

This Ring Floodlight Camera Is at Its Lowest Price Right Now Pradershika Sharma | usagoldmines.com

iOS 26 and iPadOS 26 Rumored to Feature Apple's Preview App Joe Rossignol | usagoldmines.com

How to Watch Apple's WWDC 2025 Keynote on June 9 Tim Hardwick | usagoldmines.com

Cloud service Infomaniak steps up fight with Proton over controversial Swiss surveillance law chiara...

Quordle hints and answers for Saturday, June 7 (game #1230) | usagoldmines.com

NYT Strands hints and answers for Saturday, June 7 (game #461) | usagoldmines.com

7 new movies and TV shows to stream on Netflix, Prime Video, Max, and more this weekend (June 6) tom...

NYT Connections hints and answers for Saturday, June 7 (game #727) | usagoldmines.com

IPVanish teams up with URC to promote cybersecurity outside the rugby pitch chiara.castro@futurenet....

​​Beyond algorithms: Agentic AI and the behavioral data scientist | usagoldmines.com

Bypassing implementation roadblocks: how to get the most out of your IT automation | usagoldmines.c...

OpenAI confronts user panic over court-ordered retention of ChatGPT logs Ashley Belanger | usagoldmi...

This USB-C wall plug fast-charges 4 devices — and it’s 40% off right now | usagoldmines.com

Get Lenovo’s RTX 4060 gaming laptop for only $879 while you can | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

'Screenbox' Is a Sleek and Capable VLC-Based Video Player for Windows Justin Pot | usagoldmines.com

Five Games to Play Once You've Finished 'Oblivion: Remastered' Stephen Johnson | usagoldmines.com

'iPhone 17 Air' Launching Later This Year With These 17 New Features Joe Rossignol | usagoldmines.co...

3 Apple Intelligence features we know are coming at WWDC 2025 and 3 I’d like to see as well | usago...

Anthropic is building new Claude AI models specifically for US national security designed to handle ...

DOGE used flawed AI tool to “munch” Veterans Affairs contracts Brandon Roberts, Vernal Coleman, and ...

The Full Nerd: GeForce Now on Steam Deck is awesome, USB-C spec clarity is not | usagoldmines.com

Make your Windows 11 taskbar transparent for a cool, minimalist vibe | usagoldmines.com

This fast Core i9 mini PC with 32GB RAM is down to $440 today | usagoldmines.com

30 of the Sweatiest Movies to Watch This Summer Ross Johnson | usagoldmines.com

All the Essential Camping Gear You Need This Summer (and Some Non-Essentials You'll Want) Stephen Jo...

How to Turn Your Backyard Into a Movie Theater This Summer Stephen Johnson | usagoldmines.com