PT-2025-25176 · Google+4 · Google Chrome+4

Seunghyun Lee

·

Published

2025-06-10

·

Updated

2026-03-01

·

CVE-2025-5959

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Chromium versions prior to 137.0.7151.103 Google Chrome versions prior to 137.0.7151.103
Description A type confusion issue exists in the V8 component of Google Chrome. This flaw could allow a remote attacker to execute arbitrary code within a sandbox by using a specially crafted HTML page. The vulnerability is related to errors in data type mixing within the V8 engine.
Recommendations Upgrade Chromium to version 137.0.7151.103 or later. Upgrade Google Chrome to version 137.0.7151.103 or later.

Fix

RCE

Type Confusion

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8435
BDU:2025-07100
CVE-2025-5959
DSA-5942-1
MGASA-2025-0187
OPENSUSE-SU-2025:15210-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Red Os