Where does the bug appear (feature/product)?
Cursor IDE
Describe the Bug
CVE-2025-7656 is one of the several vulnerabilities already public disclosed and patched in the latest version of Chromium, which is used by Electron, which is the engine that powers Cursor.
All Chromium versions prior to 138.x.x are vulnerables. Cursor is currently using version 132.x.
Steps to Reproduce
Ignorant users of this vulnerability could open a link that opens Cursor internal browser, prompting the IDE to execute potential malicious code locally on the userâs machine.
The BleepingComputer article (Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities) mentions:
"Upon receiving the proof-of-concept exploit, Cursor dismissed the report by saying that self-inflicted DoS is out of scope.
But the researchers noted that this stance ignores the more severe exploitation potential of the flaw, including memory-corruption primitives, or even the broader set of unpatched CVEs in the Electron apps used.
âSince their last Chromium update on 2025-03-21 for version 0.47.9 since Chromium 132.0.6834.210 was out, at least 94 known CVEs have been published. Weâve weaponized just one. The attack surface is massive,â explains Ox Security."
Expected Behavior
For Cursor devs to not look for lame excuses for not patching public disclosed vulnerabilities that can potentially harm their users because they are âout of scopeâ (the f that means?)
Screenshots / Screen Recordings
Operating System
Windows 10/11
MacOS
Linux
Current Cursor Version (Menu â About Cursor â Copy)
Version: 1.7.53
VSCode Version: 1.99.3
Commit: ab6b80c19b51fe71d58e69d8ed3802be587b3410
Date: 2025-10-20T19:15:58.572Z
Electron: 34.5.8
Chromium: 132.0.6834.210
Node.js: 20.19.1
V8: 13.2.152.41-electron.0
OS: Darwin arm64 25.0.0
Additional Information
Users working with Cursor in businesses should immediately stop using this IDE until devs publicly address and fix this vulnerabilities by simply upgrading to the latest patched version of Chromium.
Does this stop you from using Cursor
Yes - Cursor is unusable
