PT-2025-43032 · Google+3 · Google Chrome+3

CVE-2025-12036

·

Published

2025-10-21

·

Updated

2026-08-31

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 141.0.7390.122 Chromium versions prior to 141.0.7390.122
Description An out-of-bounds memory access issue exists in the V8 JavaScript engine due to inappropriate implementation of security checks for standard elements. A remote attacker can exploit this by using a crafted HTML page, potentially leading to arbitrary code execution, denial of service, or information disclosure. Technical details indicate that the Expect() and ExpectNext() functions in the JSON parser may trigger garbage collection due to the allocation of an Exception object when a failed expectation simply sets the cursor to the end of the input.
Recommendations Update to version 141.0.7390.122 or later.

Fix

RCE

DoS

Out of bounds Read

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14702
BDU:2025-13845
CVE-2025-12036
DSA-6036-1
DSA-6046-1
OPENSUSE-SU-2025:15665-1
OPENSUSE-SU-2025:20032-1

Affected Products

Alt Linux
Debian
Google Chrome
Red Os