CVE-2025-11205
- EPSS 0.09%
- Veröffentlicht 06.11.2025 22:15:38
- Zuletzt bearbeitet 13.11.2025 15:31:01
Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-11206
- EPSS 0.08%
- Veröffentlicht 06.11.2025 22:15:38
- Zuletzt bearbeitet 13.11.2025 15:30:54
Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2025-11207
- EPSS 0.04%
- Veröffentlicht 06.11.2025 22:15:38
- Zuletzt bearbeitet 13.11.2025 15:30:46
Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-11208
- EPSS 0.09%
- Veröffentlicht 06.11.2025 22:15:38
- Zuletzt bearbeitet 13.11.2025 15:30:30
Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-11209
- EPSS 0.04%
- Veröffentlicht 06.11.2025 22:15:38
- Zuletzt bearbeitet 13.11.2025 15:30:02
Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-11210
- EPSS 0.02%
- Veröffentlicht 06.11.2025 22:15:38
- Zuletzt bearbeitet 13.11.2025 15:29:47
Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-10501
- EPSS 0.18%
- Veröffentlicht 24.09.2025 17:15:39
- Zuletzt bearbeitet 25.09.2025 15:57:08
Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-10502
- EPSS 0.13%
- Veröffentlicht 24.09.2025 17:15:39
- Zuletzt bearbeitet 25.09.2025 15:56:56
Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
CVE-2025-10585
- EPSS 0.75%
- Veröffentlicht 24.09.2025 17:15:39
- Zuletzt bearbeitet 30.10.2025 15:55:01
Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-10890
- EPSS 0.05%
- Veröffentlicht 24.09.2025 17:15:39
- Zuletzt bearbeitet 25.09.2025 15:56:42
Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)