PT-2025-37011 · Google+3 · Google Chrome+3

Anon

+1

·

Published

2025-01-01

·

Updated

2025-12-03

·

CVE-2025-10201

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Chromium versions prior to 140.0.7339.127 Chromium versions 140.0.7339.127-1deb12u1 through 140.0.7339.127-1deb13u1 Chromium version 141.0.7390.76-alt0.p11.1
Description The issue involves an inappropriate implementation within the Mojo IPC library used by Google Chrome and Microsoft Edge browsers. This flaw in access control could allow a remote attacker to bypass security restrictions. Exploitation may involve crafted HTML pages to bypass site isolation. The vulnerability affects systems running Google Chrome on Android, Linux, and ChromeOS. The Mojo library's ChannelPosix component incorrectly handles a large number of file descriptors in a message, potentially leading to file descriptor confusion.
Recommendations Chromium versions prior to 140.0.7339.127: Upgrade to version 140.0.7339.127 or later. Chromium versions 140.0.7339.127-1deb12u1 through 140.0.7339.127-1deb13u1: Upgrade to a version later than 140.0.7339.127-1~deb13u1. Chromium version 141.0.7390.76-alt0.p11.1: No further action is required.

Fix

Improper Access Control

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13054
BDU:2025-11245
CVE-2025-10201
DSA-5996-1
OPENSUSE-SU-2025:15548-1

Affected Products

Alt Linux
Debian
Google Chrome
Red Os