CVE-2025-7656: High Integer overflow in V8
Chromium: CVE-2025-7656 Integer overflow in V8
Other sources
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome/Chromium V8to a version that resolves this vulnerability.Fixed in 138.0.7204.157
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7656?
The severity of CVE-2025-7656 has not been explicitly stated, but it is classified as a high risk due to its nature as a sandbox escape vulnerability.
How do I fix CVE-2025-7656?
To fix CVE-2025-7656, update Google Chrome to version 138.0.7204.157 or later.
Which versions of Chrome and Edge are affected by CVE-2025-7656?
CVE-2025-7656 affects Google Chrome versions prior to 138.0.7204.157 and Microsoft Edge (Chromium-based) versions prior to 138.0.3351.95.
Is CVE-2025-7656 actively exploited?
Yes, CVE-2025-7656 is reported to be actively exploited in the wild.
What type of vulnerability is CVE-2025-7656?
CVE-2025-7656 is classified as an integer overflow vulnerability leading to a potential sandbox escape.