CVE-2025-11215: Off by one error in V8
Chromium: CVE-2025-11215 Off by one error in V8
Other sources
Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11215?
The severity of CVE-2025-11215 is classified as high due to the potential for exploitation in Chromium-based applications.
How do I fix CVE-2025-11215?
To fix CVE-2025-11215, update your Microsoft Edge (Chromium-based) to the latest version as recommended by Microsoft.
Which products are affected by CVE-2025-11215?
CVE-2025-11215 affects Microsoft Edge (Chromium-based) and earlier versions of Microsoft Edge.
What kind of error does CVE-2025-11215 represent?
CVE-2025-11215 represents an off-by-one error in the V8 engine used in Chromium-based browsers.
Is CVE-2025-11215 addressed in later updates of Microsoft Edge?
Yes, Microsoft Edge has released updates that address CVE-2025-11215 and users are urged to apply these updates.