Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-10501

Опубликовано: 24 сент. 2025
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A vulnerability was found in the Web Real-Time Communication (WebRTC) component of chromium-browser. This flaw stems from improper memory management when processing web content. A remote attacker can exploit this vulnerability by convincing a user to visit a specially crafted, malicious website. A successful exploitation of this flaw may lead the browser to crash, to present unexpected behavior and remote code execution is not discarded.

Отчет

This vulnerability doesn't affect any supported Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2397867chromium-browser: Use after free in WebRTC

EPSS

Процентиль: 34%
0.00141
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
6 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
6 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
7 месяцев назад

Chromium: CVE-2025-10501 Use after free in WebRTC

CVSS3: 8.8
debian
6 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allo ...

CVSS3: 8.8
github
6 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 34%
0.00141
Низкий

8.8 High

CVSS3