CVE-2025-5419
- EPSS 0.6%
- Published 02.06.2025 23:36:53
- Last modified 23.06.2025 18:29:13
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-5066
- EPSS 0.09%
- Published 27.05.2025 20:43:04
- Last modified 29.05.2025 15:50:51
Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: ...
CVE-2025-5067
- EPSS 0.09%
- Published 27.05.2025 20:43:04
- Last modified 29.05.2025 15:50:43
Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-5281
- EPSS 0.09%
- Published 27.05.2025 20:43:04
- Last modified 29.05.2025 15:50:25
Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5283
- EPSS 0.11%
- Published 27.05.2025 20:43:04
- Last modified 31.05.2025 23:15:20
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5064
- EPSS 0.09%
- Published 27.05.2025 20:43:03
- Last modified 29.05.2025 15:51:09
Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5065
- EPSS 0.09%
- Published 27.05.2025 20:43:03
- Last modified 29.05.2025 15:50:57
Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5280
- EPSS 0.22%
- Published 27.05.2025 20:43:03
- Last modified 29.05.2025 15:50:31
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-5063
- EPSS 0.29%
- Published 27.05.2025 20:43:02
- Last modified 02.07.2025 14:15:26
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-4664
- EPSS 0.02%
- Published 14.05.2025 17:41:06
- Last modified 06.06.2025 01:00:02
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)