Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14766

Опубликовано: 16 дек. 2025
Источник: redhat
CVSS3: 8.8

Описание

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A flaw was found in V8 in Google Chrome. This vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HyperText Markup Language (HTML) page.

Отчет

This vulnerability is rated Critical for Red Hat as it affects the chromium-browser component. A remote attacker could exploit heap corruption via a crafted HTML page, leading to potential arbitrary code execution. User interaction, such as visiting a malicious website, is required for exploitation.

Меры по смягчению последствий

To mitigate this issue, users should avoid visiting untrusted websites or opening untrusted web content. Employing a sandboxed environment for web browsing can further reduce the risk of exploitation.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2422948chromium-browser: Google Chrome V8: Out-of-bounds read and write leads to heap corruption

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
4 месяца назад

Chromium: CVE-2025-14766 Use after free in WebGPU

CVSS3: 8.8
debian
4 месяца назад

Out of bounds read and write in V8 in Google Chrome prior to 143.0.749 ...

CVSS3: 8.8
github
4 месяца назад

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
fstec
4 месяца назад

Уязвимость обработчика JavaScript-сценариев V8 браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю вызвать отказ в обслуживании

8.8 High

CVSS3