Critical VMware Aria XSS Flaw Opens Door to Token Theft, Broadcom Warns
Broadcom has issued a critical alert concerning a serious security issue in VMware Aria automation products. This DOM-based Cross-Site Scripting (XSS) vulnerability—assigned CVE-2025-22249—poses a significant risk, as it could enable attackers to hijack access tokens from active user sessions.
Uncovered by security researchers and formally documented in advisory VMSA-2025-0008 on May 12, 2025, the flaw carries a CVSS v3 base score of 8.2. At its core, the issue stems from improper handling within the Document Object Model (DOM) layer, which can be exploited to execute malicious JavaScript in a user’s browser environment.
The threat isn’t just theoretical—if an attacker manages to trick a logged-in user into clicking a specially crafted link, they can silently extract the session’s access token and potentially gain unauthorized access to sensitive systems.
“This vulnerability can be weaponized by embedding payloads in deceptive URLs. A successful social engineering attempt could result in session hijacking without requiring system login credentials,” the advisory explains.
What makes this flaw particularly concerning is that exploitation doesn’t require prior access to the platform—just a moment of user interaction. If a user is already authenticated and clicks on a malicious link, the attacker’s script can activate within their session and siphon off authentication tokens to a remote server.
Impact Scope
Multiple VMware Aria products are affected by this vulnerability. Broadcom has released patches to address the issue and urges all users to apply updates without delay.
Impacted Products and Available Fixes
| Product | Vulnerable Versions | Remediation / Patch Details |
|---|---|---|
| VMware Aria Automation | Versions 8.18.x and earlier | Update to 8.18.1 Patch 2 |
| VMware Cloud Foundation | Versions 4.x and 5.x | Refer to Knowledge Base 394224 |
| VMware Telco Cloud Platform | Version 5.x | Apply 8.18.1 Patch 2 |
New XSS Risk Intensifies VMware Security Scrutiny Amid Recent Exploits
The discovery of this DOM-based XSS flaw comes at a time of heightened attention on VMware’s security posture. It follows a string of critical ESXi vulnerabilities (CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226) that were weaponized in real-world attacks earlier this year—adding fuel to growing concerns over the resilience of VMware’s ecosystem.
Though no public proof-of-concept or evidence of in-the-wild exploitation has surfaced for this XSS issue, security professionals caution that these types of flaws are often easy to weaponize once discovered—particularly by threat actors skilled in browser-side attack vectors.
Immediate Action Recommended
Given the lack of temporary mitigations, cybersecurity teams are strongly urged to apply the available patches without delay. In parallel, organizations should bolster their defenses through layered security practices:
- Deploy web application firewalls (WAFs) configured to block cross-site scripting payloads
- Educate employees on recognizing suspicious URLs and social engineering tactics
- Enforce multi-factor authentication (MFA) across critical systems
- Continuously monitor access logs for anomalies or signs of compromise
The vulnerability was responsibly reported by independent researcher Bartosz Reginiak, underscoring the vital role of ethical disclosure in helping vendors secure their platforms before attackers strike.
This latest development reaffirms a persistent challenge: securing enterprise-grade infrastructure is an ongoing process. In environments as intricate as VMware’s, proactive patch management remains the first and strongest line of defense.




