CVE-2025-14766
- EPSS 3.17%
- Veröffentlicht 16.12.2025 22:54:47
- Zuletzt bearbeitet 30.09.2026 17:10:00
Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-14765
- EPSS 2.93%
- Veröffentlicht 16.12.2025 22:54:46
- Zuletzt bearbeitet 30.09.2026 16:10:00
Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-14372
- EPSS 0.24%
- Veröffentlicht 12.12.2025 19:20:42
- Zuletzt bearbeitet 07.10.2026 20:10:01
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-14373
- EPSS 0.27%
- Veröffentlicht 12.12.2025 19:20:42
- Zuletzt bearbeitet 07.10.2026 20:10:01
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-14174
- EPSS 22.63%
- Veröffentlicht 12.12.2025 19:20:41
- Zuletzt bearbeitet 07.10.2026 20:10:01
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2025-13992
- EPSS 0.18%
- Veröffentlicht 03.12.2025 19:15:55
- Zuletzt bearbeitet 25.09.2026 23:10:00
Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-13633
- EPSS 0.4%
- Veröffentlicht 02.12.2025 19:15:47
- Zuletzt bearbeitet 25.09.2026 23:10:00
Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-13720
- EPSS 0.26%
- Veröffentlicht 02.12.2025 19:00:17
- Zuletzt bearbeitet 25.09.2026 23:10:00
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-13721
- EPSS 0.21%
- Veröffentlicht 02.12.2025 19:00:17
- Zuletzt bearbeitet 25.09.2026 23:10:00
Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-13640
- EPSS 0.18%
- Veröffentlicht 02.12.2025 19:00:16
- Zuletzt bearbeitet 04.12.2025 18:06:26
Inappropriate implementation in Passwords in Google Chrome prior to 143.0.7499.41 allowed a local attacker to bypass authentication via physical access to the device. (Chromium security severity: Low)