CVE-2025-0451
- EPSS 0.24%
- Published 04.02.2025 19:15:32
- Last modified 08.04.2025 12:25:41
Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity...
CVE-2025-0762
- EPSS 0.26%
- Published 29.01.2025 11:15:09
- Last modified 21.04.2025 20:53:55
Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)
CVE-2025-0611
- EPSS 0.23%
- Published 22.01.2025 20:15:30
- Last modified 18.04.2025 02:26:59
Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-0612
- EPSS 0.22%
- Published 22.01.2025 20:15:30
- Last modified 18.04.2025 02:26:13
Out of bounds memory access in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-0439
- EPSS 0.08%
- Published 15.01.2025 11:15:10
- Last modified 21.04.2025 20:52:49
Race in Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-0440
- EPSS 0.05%
- Published 15.01.2025 11:15:10
- Last modified 21.04.2025 20:53:05
Inappropriate implementation in Fullscreen in Google Chrome on Windows prior to 132.0.6834.83 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-0441
- EPSS 0.11%
- Published 15.01.2025 11:15:10
- Last modified 21.04.2025 20:53:17
Inappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially sensitive information from the system via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-0442
- EPSS 0.1%
- Published 15.01.2025 11:15:10
- Last modified 21.04.2025 20:53:28
Inappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-0443
- EPSS 0.35%
- Published 15.01.2025 11:15:10
- Last modified 21.04.2025 20:53:36
Insufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: ...
CVE-2025-0446
- EPSS 0.08%
- Published 15.01.2025 11:15:10
- Last modified 21.04.2025 20:53:41
Inappropriate implementation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Lo...