All findings

CVE-2025-12443 medium

Chrome directly credits AISLE Research on 2025 security fix

Chrome's October 2025 stable release directly credits AISLE Research on a Medium-severity WebXR out-of-bounds read.

Bug class
Out-of-bounds read
Affected codebase
Google Chrome WebXR
Credited system
AISLE
Disclosed
October 28, 2025
Attribution
Self-reported attribution
Severity
medium
Source status: Chrome's stable-channel release names AISLE Research and publishes the CVE and upstream severity. AISLE's own registry supplies the autonomous-system attribution, so the AI attribution is self-reported.

Summary

CVE-2025-12443 is a historical browser omission identified during the AISLE registry reconciliation. The Chrome release note provides direct affected- vendor credit rather than relying only on AISLE’s tracker.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.