Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-10501

Опубликовано: 24 сент. 2025
Источник: redhat
CVSS3: 8.8

Описание

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A vulnerability was found in the Web Real-Time Communication (WebRTC) component of chromium-browser. This flaw stems from improper memory management when processing web content. A remote attacker can exploit this vulnerability by convincing a user to visit a specially crafted, malicious website. A successful exploitation of this flaw may lead the browser to crash, to present unexpected behavior and remote code execution is not discarded.

Отчет

This vulnerability doesn't affect any supported Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2397867chromium-browser: Use after free in WebRTC

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
10 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
10 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
10 месяцев назад

Chromium: CVE-2025-10501 Use after free in WebRTC

CVSS3: 8.8
debian
10 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allo ...

CVSS3: 8.8
github
10 месяцев назад

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3