PT-2025-37010 · Google+3 · Google Chrome+3

Looben Yang

·

Published

2025-01-01

·

Updated

2025-11-20

·

CVE-2025-10200

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Chromium versions prior to 140.0.7339.127 Microsoft Edge (Chromium-based) versions prior to 140.0.7339.127 Vivaldi versions prior to 138.0.7204.261
Description A critical use-after-free issue exists in the Serviceworker component of Chromium. This flaw could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page, potentially leading to arbitrary code execution or denial of service. The vulnerability is related to a race condition between handling request timeouts and starting new requests within the ServiceWorker, resulting in a use-after-free condition. A researcher discovered the issue and was awarded a $43,000 bounty by Google. There have been no confirmed reports of active exploitation in the wild. The Serviceworker component is susceptible to this flaw.
Recommendations Chromium versions prior to 140.0.7339.127: Upgrade to version 140.0.7339.127 or later. Microsoft Edge (Chromium-based) versions prior to 140.0.7339.127: Upgrade to version 140.0.7339.127 or later. Vivaldi versions prior to 138.0.7204.261: Upgrade to version 138.0.7204.261 or later.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13054
BDU:2025-11244
CVE-2025-10200
DSA-5996-1
OPENSUSE-SU-2025:15548-1

Affected Products

Alt Linux
Debian
Google Chrome
Red Os