Where
-Infinity
0
Severity
5.4
EPSS
0.06%
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE-2025-5281 Inappropriate implementation in BFCache

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
EPSS
0.08%
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

A double-free could have occurred in vpxcodecencinitmulti after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.

1 / 5
Source: Red Hat
First published (updated )
Severity
8.8
EPSS
0.09%
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-3620 Use after free in USB

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
EPSS
0.07%
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-4096 Heap buffer overflow in HTML

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
EPSS
0.14%
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-3619 Heap buffer overflow in Codecs

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
EPSS
0.07%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-4050 Out of bounds memory access in DevTools

1 / 3
Source: Microsoft
First published (updated )
Severity
6.3
EPSS
0.03%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Chromium: CVE-2025-4051 Insufficient data validation in DevTools

1 / 3
Source: Microsoft
First published (updated )
Severity
9.8
EPSS
0.04%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Chromium: CVE-2025-4052 Inappropriate implementation in DevTools

1 / 3
Source: Microsoft
First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-21404.

First published (updated )
Advisory
ZDI-25-090

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2025-21404.

First published (updated )
Severity
8.8
Use After Free, Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-1426 Heap buffer overflow in GPU

1 / 3
Source: Microsoft
First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file while in Internet Explorer mode. The ZDI has assigned a CVSS rating of 7.5.

First published (updated )
Advisory
ZDI-25-083

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file while in Internet Explorer mode. The ZDI has assigned a CVSS rating of 7.5.

First published (updated )
Severity
8.8
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-0999 Heap buffer overflow in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
EPSS
0.11%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE-2025-3074 Inappropriate implementation in Downloads

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE-2025-0445 Use after free in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE -2025-0995 Use after free in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE -2025-0996 Inappropriate implementation in Browser UI

1 / 3
Source: Microsoft
First published (updated )
Severity
8.1
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Chromium: CVE -2025-0997 Use after free in Navigation

1 / 3
Source: Microsoft
First published (updated )
Severity
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Chromium: CVE-2025-0612 Out of bounds memory access in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
6.3
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Chromium: CVE-2025-0444 Use after free in Skia

1 / 3
Source: Microsoft
First published (updated )
EPSS
0.04%
Buffer Overflow

Chromium: CVE-2025-0438 Stack buffer overflow in Tracing

1 / 3
Source: Microsoft
First published (updated )
Severity
8.8
EPSS
0.06%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Chromium: CVE-2025-0437 Out of bounds read in Metrics

1 / 3
Source: Microsoft
First published (updated )
Severity
5.4
EPSS
0.11%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Chromium: CVE-2025-3073 Inappropriate implementation in Autofill

1 / 3
Source: Microsoft
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Chromium: CVE-2025-1921 Inappropriate Implementation in Media Stream

1 / 3
Source: Microsoft
First published (updated )
Severity
9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Chromium: CVE -2025-0998 Out of bounds memory access in V8

1 / 3
Source: Microsoft
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Chromium: CVE-2025-0611 Object corruption in V8

1 / 3
Source: Microsoft
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203