PT-2025-37010 · Google+3 · Google Chrome+3
Looben Yang
·
Published
2025-01-01
·
Updated
2025-11-20
·
CVE-2025-10200
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Chromium versions prior to 140.0.7339.127
Microsoft Edge (Chromium-based) versions prior to 140.0.7339.127
Vivaldi versions prior to 138.0.7204.261
Description
A critical use-after-free issue exists in the Serviceworker component of Chromium. This flaw could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page, potentially leading to arbitrary code execution or denial of service. The vulnerability is related to a race condition between handling request timeouts and starting new requests within the ServiceWorker, resulting in a use-after-free condition. A researcher discovered the issue and was awarded a $43,000 bounty by Google. There have been no confirmed reports of active exploitation in the wild. The
Serviceworker component is susceptible to this flaw.Recommendations
Chromium versions prior to 140.0.7339.127: Upgrade to version 140.0.7339.127 or later.
Microsoft Edge (Chromium-based) versions prior to 140.0.7339.127: Upgrade to version 140.0.7339.127 or later.
Vivaldi versions prior to 138.0.7204.261: Upgrade to version 138.0.7204.261 or later.
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Google Chrome
Red Os