5 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

13 Aug 2025 — Use after free in Aura in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 139.0.7258.127-1~deb12u1. For the st... • https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html • CWE-416: Use After Free •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

13 Aug 2025 — Inappropriate implementation in File Picker in Google Chrome prior to 139.0.7258.127 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 139.0.7258.127-1~deb12u1. Fo... • https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html • CWE-303: Incorrect Implementation of Authentication Algorithm CWE-346: Origin Validation Error •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

13 Aug 2025 — Out of bounds write in ANGLE in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 139.0.7258.127-1~deb12u1. For the stable distribution (trixie), these problems have bee... • https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html • CWE-787: Out-of-bounds Write •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

13 Aug 2025 — Race in V8 in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 139.0.7258.127-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in ver... • https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

13 Aug 2025 — Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High) Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 139.0.7258.127-1~deb12u1. For the stable distribution (trixie), these problems ... • https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html • CWE-122: Heap-based Buffer Overflow •