PT-2025-25176 · Google+4 · Google Chrome+4
Seunghyun Lee
·
Published
2025-06-10
·
Updated
2026-03-01
·
CVE-2025-5959
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Chromium versions prior to 137.0.7151.103
Google Chrome versions prior to 137.0.7151.103
Description
A type confusion issue exists in the V8 component of Google Chrome. This flaw could allow a remote attacker to execute arbitrary code within a sandbox by using a specially crafted HTML page. The vulnerability is related to errors in data type mixing within the V8 engine.
Recommendations
Upgrade Chromium to version 137.0.7151.103 or later.
Upgrade Google Chrome to version 137.0.7151.103 or later.
Fix
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Google Chrome
Red Os