CVE-2025-8577
- EPSS 0.06%
- Published 07.08.2025 01:30:38
- Last modified 08.08.2025 18:24:45
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: M...
CVE-2025-8578
- EPSS 0.15%
- Published 07.08.2025 01:30:38
- Last modified 11.08.2025 14:15:27
Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-8292
- EPSS 0.13%
- Published 30.07.2025 01:18:27
- Last modified 01.08.2025 14:37:02
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-8010
- EPSS 0.1%
- Published 22.07.2025 21:11:18
- Last modified 26.09.2025 17:33:32
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-8011
- EPSS 0.1%
- Published 22.07.2025 21:11:18
- Last modified 26.09.2025 17:33:44
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-6558
- EPSS 0.05%
- Published 15.07.2025 18:15:24
- Last modified 23.07.2025 01:00:01
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2025-7656
- EPSS 0.1%
- Published 15.07.2025 18:15:24
- Last modified 16.07.2025 14:28:06
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-7657
- EPSS 0.17%
- Published 15.07.2025 18:15:24
- Last modified 16.07.2025 14:27:43
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-34092
- EPSS 0%
- Published 02.07.2025 19:25:35
- Last modified 24.07.2025 07:15:53
Rejected reason: Neither filed by Chrome nor a valid security vulnerability.
CVE-2025-34091
- EPSS 0%
- Published 02.07.2025 19:25:27
- Last modified 24.07.2025 07:15:53
Rejected reason: Neither filed by Chrome nor a valid security vulnerability.