CVE-2025-4664: Google Chrome’s Zero-Day Flaw Exploited in the Wild

Red | Vulnerability Report
Download PDF

CVE-2025-4664 is a medium-severity zero-day vulnerability in Google Chrome’s Loader component, allowing attackers to leak cross-origin data via crafted HTML pages. It exploits Chrome’s handling of the Link header to set an unsafe referrer policy, exposing sensitive query parameters like OAuth tokens. Exploitation requires user interaction, such as visiting a malicious site. Google confirmed active exploitation, and users are urged to update Chrome immediately.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox