CVE-2025-48883 - CVE House
Back to Database
Status published Medium CVE-2025-48883

Chrome PHP is missing encoding in `CssSelector`

Vulnerability Description

Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities. This is patched in v1.14.0. As a workaround, users can apply encoding manually to their selectors if they are unable to upgrade.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48883

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

chrome
Vulnerable Versions:
< 1.14.0

Timeline

Official Publish: May 30th, 2025
Last Modified: May 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)