CVE-2025-12727: Inappropriate implementation in V8
Chromium: CVE-2025-12727 Inappropriate implementation in V8
Other sources
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 142.0.7444.137
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12727?
CVE-2025-12727 is classified with a severity rating that indicates potential risk levels associated with the vulnerability.
How do I fix CVE-2025-12727?
To fix CVE-2025-12727, update Google Chrome to version 142.0.7444.135 or later, or update Microsoft Edge (Chromium-based) to the latest version as provided by Microsoft.
Which applications are affected by CVE-2025-12727?
CVE-2025-12727 affects Google Chrome versions up to 142.0.7444.134 and Microsoft Edge (Chromium-based) using the same Chromium codebase.
Is Google Chrome the only browser affected by CVE-2025-12727?
No, Microsoft Edge (Chromium-based) is also affected due to its reliance on the Chromium engine used by Google Chrome.
What is the nature of CVE-2025-12727?
CVE-2025-12727 involves an inappropriate implementation in the V8 JavaScript engine, which could lead to potential exploitation.