CVE-2025-12909
- EPSS 0.04%
- Veröffentlicht 07.11.2025 23:23:38
- Zuletzt bearbeitet 21.11.2025 21:19:25
Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity: Low)
CVE-2025-12906
- EPSS 0.07%
- Veröffentlicht 07.11.2025 23:23:37
- Zuletzt bearbeitet 21.11.2025 21:21:10
Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-12907
- EPSS 0.12%
- Veröffentlicht 07.11.2025 23:23:37
- Zuletzt bearbeitet 21.11.2025 21:20:47
Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to execute arbitrary code via user action in Devtools. (Chromium security severity: Low)
CVE-2025-12905
- EPSS 0.01%
- Veröffentlicht 07.11.2025 23:23:36
- Zuletzt bearbeitet 21.11.2025 21:21:31
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker to bypass Mark of the Web via a crafted HTML page. (Chromium security severity: Low)
CVE-2025-11458
- EPSS 0.04%
- Veröffentlicht 06.11.2025 22:26:49
- Zuletzt bearbeitet 25.11.2025 14:49:31
Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVE-2025-11460
- EPSS 0.14%
- Veröffentlicht 06.11.2025 22:26:49
- Zuletzt bearbeitet 25.11.2025 14:48:58
Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)
CVE-2025-11756
- EPSS 0.12%
- Veröffentlicht 06.11.2025 22:26:20
- Zuletzt bearbeitet 25.11.2025 14:48:32
Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2025-12036
- EPSS 0.09%
- Veröffentlicht 06.11.2025 22:24:32
- Zuletzt bearbeitet 25.11.2025 14:45:59
Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2025-11211
- EPSS 0.04%
- Veröffentlicht 06.11.2025 22:15:39
- Zuletzt bearbeitet 13.11.2025 15:29:40
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-11212
- EPSS 0.07%
- Veröffentlicht 06.11.2025 22:15:39
- Zuletzt bearbeitet 13.11.2025 15:29:31
Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity:...