CVE-2025-5065
- EPSS 0.09%
- Published 27.05.2025 20:43:03
- Last modified 29.05.2025 15:50:57
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5280
- EPSS 0.22%
- Published 27.05.2025 20:43:03
- Last modified 29.05.2025 15:50:31
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-5063
- EPSS 0.29%
- Published 27.05.2025 20:43:02
- Last modified 02.07.2025 14:15:26
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-4664
- EPSS 0.02%
- Published 14.05.2025 17:41:06
- Last modified 06.06.2025 01:00:02
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVE-2025-4372
- EPSS 0.04%
- Published 06.05.2025 21:35:44
- Last modified 28.05.2025 20:00:04
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-4051
- EPSS 0.02%
- Published 05.05.2025 18:15:44
- Last modified 28.05.2025 20:08:14
Insufficient data validation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security sever...
CVE-2025-4052
- EPSS 0.03%
- Published 05.05.2025 18:15:44
- Last modified 28.05.2025 20:07:45
Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security sever...
CVE-2025-4096
- EPSS 0.04%
- Published 05.05.2025 18:15:44
- Last modified 28.05.2025 20:07:18
Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-4050
- EPSS 0.03%
- Published 05.05.2025 18:15:43
- Last modified 28.05.2025 20:08:51
Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severi...
CVE-2025-3620
- EPSS 0.05%
- Published 16.04.2025 20:57:45
- Last modified 23.04.2025 18:11:43
Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)