CVE-2025-12434
- EPSS 0.06%
- Veröffentlicht 10.11.2025 20:00:16
- Zuletzt bearbeitet 13.11.2025 15:25:28
Race in Storage in Google Chrome on Windows prior to 142.0.7444.59 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-12432
- EPSS 0.07%
- Veröffentlicht 10.11.2025 20:00:15
- Zuletzt bearbeitet 13.11.2025 15:26:15
Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-12433
- EPSS 0.03%
- Veröffentlicht 10.11.2025 20:00:15
- Zuletzt bearbeitet 13.11.2025 15:26:04
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2025-12430
- EPSS 0.04%
- Veröffentlicht 10.11.2025 20:00:14
- Zuletzt bearbeitet 13.11.2025 15:26:35
Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
CVE-2025-12431
- EPSS 0.02%
- Veröffentlicht 10.11.2025 20:00:14
- Zuletzt bearbeitet 13.11.2025 15:26:24
Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity...
CVE-2025-12429
- EPSS 0.08%
- Veröffentlicht 10.11.2025 20:00:13
- Zuletzt bearbeitet 13.11.2025 15:26:46
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2025-12428
- EPSS 0.11%
- Veröffentlicht 10.11.2025 20:00:12
- Zuletzt bearbeitet 13.11.2025 15:26:57
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2025-12910
- EPSS 0.01%
- Veröffentlicht 07.11.2025 23:23:39
- Zuletzt bearbeitet 21.11.2025 21:19:05
Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium security severity: Low)
CVE-2025-12911
- EPSS 0.02%
- Veröffentlicht 07.11.2025 23:23:39
- Zuletzt bearbeitet 21.11.2025 21:18:16
Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-12908
- EPSS 0.08%
- Veröffentlicht 07.11.2025 23:23:38
- Zuletzt bearbeitet 21.11.2025 21:19:55
Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)