CVE-2025-8879
- EPSS 0.1%
- Published 13.08.2025 03:15:33
- Last modified 26.09.2025 17:33:53
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)
CVE-2025-8583
- EPSS 0.04%
- Published 07.08.2025 01:30:40
- Last modified 08.08.2025 18:23:49
Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8579
- EPSS 0.06%
- Published 07.08.2025 01:30:39
- Last modified 08.08.2025 18:24:30
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: L...
CVE-2025-8580
- EPSS 0.06%
- Published 07.08.2025 01:30:39
- Last modified 08.08.2025 18:24:21
Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8581
- EPSS 0.05%
- Published 07.08.2025 01:30:39
- Last modified 08.08.2025 18:24:14
Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8582
- EPSS 0.11%
- Published 07.08.2025 01:30:39
- Last modified 11.08.2025 14:15:27
Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8576
- EPSS 0.15%
- Published 07.08.2025 01:30:38
- Last modified 11.08.2025 14:15:26
Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
CVE-2025-8577
- EPSS 0.06%
- Published 07.08.2025 01:30:38
- Last modified 08.08.2025 18:24:45
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: M...
CVE-2025-8578
- EPSS 0.15%
- Published 07.08.2025 01:30:38
- Last modified 11.08.2025 14:15:27
Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-8292
- EPSS 0.13%
- Published 30.07.2025 01:18:27
- Last modified 01.08.2025 14:37:02
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)