Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryinitial-access-method

Google patches multiple Chrome V8 flaws enabling web-based remote code execution

Updated 11d agoFirst seen Jun 12, 20267 sources

Google released Chrome fixes for multiple high-severity vulnerabilities in the V8 JavaScript engine, including CVE-2025-10891, CVE-2025-10892, and CVE-2025-9864, that could be triggered when a user visits a malicious web page. The flaws include integer overflows and a use-after-free condition that can cause heap corruption in the browser renderer and potentially lead to arbitrary code execution. A related bulletin also lists CVE-2025-10890, a V8 side-channel information disclosure issue, alongside the two integer overflow bugs, warning that successful exploitation could expose sensitive data or enable full system compromise.

Google said the affected Chrome builds were patched across Windows, macOS, and Linux in the 140.0.7339 release line, with fixes landing in versions including 140.0.7339.80/.81 and later 140.0.7339.207/.208 depending on the flaw and platform. Several of the vulnerabilities were reportedly identified by Google’s AI-based Big Sleep system, and no public proof-of-concept exploits were cited in the referenced reports. Organizations using Chrome or Chromium-based browsers were urged to deploy the vendor updates promptly because the bugs are reachable through routine web browsing and may also affect downstream browsers that have not yet incorporated the upstream patches.

Share:
Google patches multiple Chrome V8 flaws enabling web-based remote code execution
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 1, 20266mo ago

Security bulletin documents three Chrome V8 vulnerabilities

A bulletin described three Google Chrome V8 vulnerabilities: CVE-2025-10890, CVE-2025-10891, and CVE-2025-10892. It states CVE-2025-10890 enables information disclosure and the other two integer overflow flaws can allow remote code execution, and recommends applying the vendor update.

SB20250923100 - Multiple vulnerabilities in Google Chrome
Sep 24, 20259mo ago

Google patches Chrome V8 flaws CVE-2025-10891 and CVE-2025-10892

Google fixed high-severity integer overflow vulnerabilities CVE-2025-10891 and CVE-2025-10892 in Chrome's V8 JavaScript engine in version 140.0.7339.207/.208. The flaws could allow heap corruption and potentially arbitrary code execution when a victim visits a malicious web page, and the content says they were discovered by Google's Big Sleep system.

Chrome V8 Integer Overflow (CVE-2025-10891): Brief Summary and Patch Details - ZeroPath Blog | ZeroPath

Chrome 140.0.7339.185/.186 patches ANGLE flaw CVE-2025-10502

Google patched CVE-2025-10502, a heap buffer overflow in Chrome's ANGLE graphics engine, by adding stricter bounds checking. The flaw affected Chrome on Windows, macOS, and Linux before versions 140.0.7339.185 or 140.0.7339.186 depending on platform.

Google Chrome ANGLE Heap Buffer Overflow (CVE-2025-10502): Brief Summary and Patch Guidance - ZeroPath Blog | ZeroPath
Sep 5, 202510mo ago

Google issues September 2025 Android patch for CVE-2025-32320

Google's September 2025 Android Security Bulletin addressed CVE-2025-32320, a local privilege escalation flaw in Android 16 System UI that could let attackers access images belonging to other users on a shared device. The content states affected devices are those prior to security patch level 2025-09-05.

Android System UI CVE-2025-32320: Brief Summary of a Confused Deputy Privilege Escalation Vulnerability - ZeroPath Blog | ZeroPath
Sep 3, 202510mo ago

Chrome 140.0.7339.80/.81 fixes V8 use-after-free CVE-2025-9864

Google made fixes available for CVE-2025-9864, a high-severity use-after-free vulnerability in Chrome's V8 engine that could be triggered via a malicious web page. The patched versions are Chrome 140.0.7339.80 for Linux and 140.0.7339.80/.81 for Windows and Mac.

Google Chrome V8 Use-After-Free (CVE-2025-9864): Brief Summary and Technical Review - ZeroPath Blog | ZeroPath
Jul 1, 20251y ago

Google patches Android Skia flaw CVE-2025-32318 in Android 16

Google addressed CVE-2025-32318, a critical heap-based buffer overflow in the Skia graphics engine, through Android 16 System component patches integrated into AOSP. The content says users should update to security patch level 2025-07-01 or later.

Android Skia Heap Buffer Overflow (CVE-2025-32318): Brief Summary and Patch Guidance - ZeroPath Blog | ZeroPath
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google patches multiple Chrome V8 flaws enabling web-based remote code execution | Mallory