PT-2025-39218 · Openssl +2 · Openssl +2
Published
2025-01-01
·
Updated
2025-09-26
·
CVE-2025-10891
8.8
High
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 140.0.7339.207
Chromium (affected versions not specified)
**Description**
An integer overflow exists in the V8 JavaScript engine used in Google Chrome and Chromium-based browsers. This issue could allow a remote attacker to exploit heap corruption through a crafted HTML page. The vulnerability may lead to remote code execution. An estimated number of affected devices or real-world incidents are not specified in the provided data. The vulnerability involves an integer overflow within the `V8` engine. No specific API endpoints or vulnerable parameters are mentioned.
**Recommendations**
Update Google Chrome to version 140.0.7339.207 or later.
Update Chromium-based browsers to a version that addresses this vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Weakness Enumeration
Related Identifiers
Affected Products
References · 18
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10891 · Security Note
- https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_23.html · Vendor Advisory
- https://security-tracker.debian.org/tracker/source-package/chromium · Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2025-10891 · Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-10891 · Security Note
- https://twitter.com/0xi6r/status/1971658151142609105 · Twitter Post
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2025-10891 · Note
- https://twitter.com/ZeroPathLabs/status/1970916104747811054 · Twitter Post
- https://reddit.com/r/chrome/comments/1norwtx/stable_channel_updated_to_14007339207208 · Reddit Post
- https://twitter.com/VulmonFeeds/status/1970931040983142447 · Twitter Post
- https://packages.debian.org/src:chromium · Note
- https://reddit.com/r/DefenceProfessionals/comments/1nph1xq/google_urgently_patches_chrome_for_critical · Reddit Post
- https://t.me/msrcreports/2158 · Telegram Post
- https://issues.chromium.org/issues/443765373 · Note
- https://crbug.com/443765373 · Note