Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-6554

Опубликовано: 30 июн. 2025
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

A flaw was found in chromium. A type confusion vulnerability in the V8 JavaScript engine allows a remote attacker to achieve arbitrary read and write operations via a specially crafted HTML page. This allows an attacker to potentially manipulate memory contents. The exploitation vector involves the processing of malicious HTML content. This can lead to arbitrary code execution.

Отчет

Chromium is not shipped in any supported Red Hat offerings.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Ссылки на источники

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2375684chromium: Chrome V8 Type Confusion Read/Write

EPSS

Процентиль: 90%
0.05303
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
16 дней назад

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

msrc
15 дней назад

Chromium: CVE-2025-6554 Type Confusion in V8

CVSS3: 8.1
debian
16 дней назад

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a ...

CVSS3: 8.1
github
15 дней назад

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
fstec
17 дней назад

Уязвимость обработчика JavaScript-сценариев V8 браузера Google Chrome, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов

EPSS

Процентиль: 90%
0.05303
Низкий

8.8 High

CVSS3