CVE-2025-10892: Integer overflow in V8
Chromium: CVE-2025-10892 Integer overflow in V8
Other sources
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10892?
CVE-2025-10892 has a high severity rating due to potential heap corruption that can be exploited remotely.
How do I fix CVE-2025-10892?
To fix CVE-2025-10892, update Google Chrome to version 140.0.7339.207 or later.
What is the impact of CVE-2025-10892 on affected systems?
The impact of CVE-2025-10892 includes the possibility of remote code execution through crafted HTML pages.
Which versions of Google Chrome are affected by CVE-2025-10892?
Google Chrome versions prior to 140.0.7339.207 are affected by CVE-2025-10892.
Can CVE-2025-10892 be exploited without user interaction?
Yes, CVE-2025-10892 can potentially be exploited by a remote attacker without requiring user interaction.