CVE-2025-12428
- EPSS 0.08%
- Veröffentlicht 10.11.2025 20:00:12
- Zuletzt bearbeitet 13.11.2025 15:26:57
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2025-12910
- EPSS 0.01%
- Veröffentlicht 07.11.2025 23:23:39
- Zuletzt bearbeitet 21.11.2025 21:19:05
Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low)
CVE-2025-12911
- EPSS 0.03%
- Veröffentlicht 07.11.2025 23:23:39
- Zuletzt bearbeitet 21.11.2025 21:18:16
Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-12908
- EPSS 0.17%
- Veröffentlicht 07.11.2025 23:23:38
- Zuletzt bearbeitet 21.11.2025 21:19:55
Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-12909
- EPSS 0.07%
- Veröffentlicht 07.11.2025 23:23:38
- Zuletzt bearbeitet 21.11.2025 21:19:25
Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low)
CVE-2025-12906
- EPSS 0.11%
- Veröffentlicht 07.11.2025 23:23:37
- Zuletzt bearbeitet 21.11.2025 21:21:10
Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-12907
- EPSS 0.26%
- Veröffentlicht 07.11.2025 23:23:37
- Zuletzt bearbeitet 21.11.2025 21:20:47
Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)
CVE-2025-12905
- EPSS 0.02%
- Veröffentlicht 07.11.2025 23:23:36
- Zuletzt bearbeitet 21.11.2025 21:21:31
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-11458
- EPSS 0.04%
- Veröffentlicht 06.11.2025 22:26:49
- Zuletzt bearbeitet 25.11.2025 14:49:31
Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVE-2025-11460
- EPSS 0.09%
- Veröffentlicht 06.11.2025 22:26:49
- Zuletzt bearbeitet 25.11.2025 14:48:58
Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)