PT-2025-43032 · Google+3 · Google Chrome+3
CVE-2025-12036
·
Published
2025-10-21
·
Updated
2026-08-31
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 141.0.7390.122
Chromium versions prior to 141.0.7390.122
Description
An out-of-bounds memory access issue exists in the V8 JavaScript engine due to inappropriate implementation of security checks for standard elements. A remote attacker can exploit this by using a crafted HTML page, potentially leading to arbitrary code execution, denial of service, or information disclosure. Technical details indicate that the
Expect() and ExpectNext() functions in the JSON parser may trigger garbage collection due to the allocation of an Exception object when a failed expectation simply sets the cursor to the end of the input.Recommendations
Update to version 141.0.7390.122 or later.
Fix
RCE
DoS
Out of bounds Read
Improperly Implemented Security Check for Standard
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Google Chrome
Red Os