PT-2025-39218 · Openssl +2 · Openssl +2

Published

2025-01-01

·

Updated

2025-09-26

·

CVE-2025-10891

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions**

Google Chrome versions prior to 140.0.7339.207

Chromium (affected versions not specified)

**Description**

An integer overflow exists in the V8 JavaScript engine used in Google Chrome and Chromium-based browsers. This issue could allow a remote attacker to exploit heap corruption through a crafted HTML page. The vulnerability may lead to remote code execution. An estimated number of affected devices or real-world incidents are not specified in the provided data. The vulnerability involves an integer overflow within the `V8` engine. No specific API endpoints or vulnerable parameters are mentioned.

**Recommendations**

Update Google Chrome to version 140.0.7339.207 or later.

Update Chromium-based browsers to a version that addresses this vulnerability.

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-10891

Affected Products

Debian
Google Chrome
Openssl