CVE-2025-8882
- EPSS 0.14%
- Veröffentlicht 13.08.2025 03:15:39
- Zuletzt bearbeitet 14.08.2025 01:07:41
Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-8881
- EPSS 0.02%
- Veröffentlicht 13.08.2025 03:15:38
- Zuletzt bearbeitet 14.08.2025 01:07:16
Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medi...
CVE-2025-8880
- EPSS 0.09%
- Veröffentlicht 13.08.2025 03:15:37
- Zuletzt bearbeitet 14.08.2025 01:07:29
Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2025-8879
- EPSS 0.09%
- Veröffentlicht 13.08.2025 03:15:33
- Zuletzt bearbeitet 26.09.2025 17:33:53
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)
CVE-2025-8583
- EPSS 0.05%
- Veröffentlicht 07.08.2025 01:30:40
- Zuletzt bearbeitet 08.08.2025 18:23:49
Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8579
- EPSS 0.07%
- Veröffentlicht 07.08.2025 01:30:39
- Zuletzt bearbeitet 08.08.2025 18:24:30
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: L...
CVE-2025-8580
- EPSS 0.07%
- Veröffentlicht 07.08.2025 01:30:39
- Zuletzt bearbeitet 08.08.2025 18:24:21
Inappropriate implementation in Filesystems in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8581
- EPSS 0.07%
- Veröffentlicht 07.08.2025 01:30:39
- Zuletzt bearbeitet 08.08.2025 18:24:14
Inappropriate implementation in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8582
- EPSS 0.09%
- Veröffentlicht 07.08.2025 01:30:39
- Zuletzt bearbeitet 13.11.2025 18:46:49
Insufficient validation of untrusted input in Core in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-8576
- EPSS 0.19%
- Veröffentlicht 07.08.2025 01:30:38
- Zuletzt bearbeitet 13.11.2025 17:59:00
Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)