CVE-2025-0291

Published Jan 8, 2025

Last updated 11 days ago

Overview

Description
Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

chrome-cve-admin@google.com
CWE-843
nvd@nist.gov
CWE-843
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-843

Social media

Hype score
Not currently trending
  1. Google Chrome の脆弱性 CVE-2025-0611/0612 が FIX:ただちにパッチを! https://t.co/cqHeu1iBqR 今年に入ってからの2度目の Chrome アップデートです。前回は 2025/01/07 の「Chrome の深刻な脆弱性 CVE-2025-0291 が FIX:ただちにアップデートを!」です。 #Browser #Chrome #CVE20250611… https://t.co/VINuxbxmlC

    @iototsecnews

    31 Jan 2025

    148 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 1/9 Urgent: @googlechrome 131 patches a critical type confusion flaw (CVE-2025-0291). Update now to prevent data breaches! 🔒 #ChromeUpdate #CyberSecurity

    @Eth1calHackrZ

    12 Jan 2025

    41 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 ¡Actualiza tu Chrome ahora! La nueva versión para Windows, Mac y Linux, ya está disponible. Incluye 4 correcciones de seguridad, destacando una vulnerabilidad crítica en V8 (CVE-2025-0291) Más detalles aquí: [oai_citation_attribution:0‡Telconet CSIRT](https://t.co/peNMRaLYWU)

    @Megabyt79042961

    11 Jan 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. СРОЧНО обновляем Chrome, Firefox и Windows: опасная уязвимость CVE-2025-0291 получает полный контроль над вашим компом! Разработчики только что выкатили патч, который устраняет хак. На Винде и Маке нужно загрузить обнову 31.0.6778.264/265, на Линуксе — 131.0.6778.264. https://t.

    @lvoropaeva

    9 Jan 2025

    405 Impressions

    3 Retweets

    4 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-0291 Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium se… https://t.co/EpghqTdhOO

    @CVEnew

    8 Jan 2025

    259 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️ Google Chromeに緊急セキュリティアップデート配信中 重大な脆弱性(CVE-2025-0291)が発見され、全プラットフォームに影響 発見者には55,000円の報奨金が支払われるほどの深刻な問題です 対象バージョン: Windows/Mac:131.0.6778.264/.265 Linux:131.0.6778.264 Android:131.0.6778.260 🔐… https://t.co/BSOW3ljPhd https://t.co/pMScpSl3m9

    @TechTrendsJP

    8 Jan 2025

    99 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Google wypłacił ~230000PLN ($55000) za zgłoszenie podatności w Chrome. Innymi słowy - łatajcie swoją przeglądarkę (CVE-2025-0291)

    @Sekurak

    8 Jan 2025

    6450 Impressions

    5 Retweets

    91 Likes

    9 Bookmarks

    7 Replies

    0 Quotes

  8. Google Chromeで深刻な脆弱性が修正された。CVE-2025-0291はV8 JavaScriptエンジンにおける型の取り違え。報奨金額55,000ドル。 https://t.co/eUg9Z9vd2P メモ:報奨金額的に大物 https://t.co/3InB2UYdSS

    @__kokumoto

    8 Jan 2025

    2616 Impressions

    7 Retweets

    32 Likes

    8 Bookmarks

    1 Reply

    0 Quotes

  9. chromeに更新入りました! 131.0.6778.205 Chrome Update Addresses High-Severity Vulnerability: CVE-2025-0291 https://t.co/AahIQGX2qZ https://t.co/6sk3NlehSK

    @NSaito_tokyo

    8 Jan 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations