CVE-2025-13640
vulnerability analysis and mitigation

Overview

CVE-2025-13640 is an inappropriate implementation vulnerability in the Passwords component of Google Chrome that allows a local attacker to bypass authentication via physical access to the device. It was reported anonymously on October 14, 2025, and publicly disclosed on December 2, 2025, as part of the Chrome 143 stable channel release. The vulnerability affects all Google Chrome versions prior to 143.0.7499.41 (Windows/Mac) and 143.0.7499.40 (Linux), as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 3.5 (Low), reflecting its physical access requirement (Chrome Releases, Microsoft MSRC).

Technical details

The vulnerability is classified under CWE as an inappropriate implementation (improper enforcement of authentication) within Chrome's built-in password management subsystem. An attacker with physical access to an unlocked or accessible device can exploit a flaw in how Chrome's Passwords feature enforces authentication checks, potentially circumventing the re-authentication prompt or lock mechanism that protects stored credentials. The Chromium issue tracker references bug ID 452071826, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases). No public proof-of-concept exploit code has been identified.

Impact

An attacker with physical access to a device running a vulnerable version of Chrome could bypass authentication controls in the browser's password manager, potentially gaining unauthorized access to stored credentials and other sensitive password-protected information. The confidentiality and integrity impacts are rated as low, and there is no availability impact, limiting the scope to scenarios where an adversary can directly interact with the target device. Lateral movement risk is minimal given the physical access prerequisite, but exposure of stored passwords could enable further account compromise (Chrome Releases).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2025-13640. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires physical access to the target device, significantly limiting the attacker pool and overall risk (Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 143.0.7499.41 (Windows/Mac) and 143.0.7499.40 (Linux), released December 2, 2025. Users should update Chrome to the latest stable version immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). As supplementary mitigations, organizations should enforce physical device security measures such as screen lock with strong authentication, full-disk encryption, and policies against leaving devices unattended. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 143 update, which included 13 security fixes, received broad coverage from security media outlets including GBHackers, Forbes, BleepingComputer, and Sophos, primarily focused on the higher-severity vulnerabilities in the same release batch. CVE-2025-13640 itself, rated Low severity, attracted minimal individual commentary given its physical-access-only attack vector. The December 2025 Patch Tuesday review by Zero Day Initiative and Rapid7 noted the Chrome update in the context of the broader monthly security landscape (GBHackers, Sophos).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management