CVE-2025-10890

Published Sep 24, 2025

Last updated 16 days ago

Overview

Description
Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed
Products
chrome

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

chrome-cve-admin@google.com
CWE-1300
nvd@nist.gov
CWE-203
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-203

Social media

Hype score
Not currently trending
  1. ⚠️Vulnerabilidades en productos Google Chrome ❗CVE-2025-10890 ❗CVE-2025-10891 ❗CVE-2025-10892 ➡️Más info: https://t.co/yyPyKTfjHK https://t.co/I4ThIO9JKr

    @CERTpy

    30 Sept 2025

    98 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 今週、ChromeとEdgeでアップデートされた脆弱性 CVE-2025-10890、CISAの評価はクリティカル(Critical)なのか。 【セキュリティ ニュース】「MS Edge」の脆弱性3件を修正 - 一部「クリティカル」との評価も(2ページ目

    @memory_o_f_snow

    27 Sept 2025

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔒 Did you know? CVE-2025-10890 reveals a sneaky side-channel leak in the V8 engine! Time to check your Chrome & Edge versions—security first, browser surfing second! 🏄‍♂️ #WindowsForum #BrowserSecurity #StaySafe https://t.co/LhLPxsuxcD

    @windowsforum

    25 Sept 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🤔 (CVE-2025-10890)[430336833]Timing attacks(SCA) on v8 string table(information leakage) https://t.co/vevSO2nHC3 https://t.co/2Vrc1Guw5x https://t.co/ofvwHiSQrd Reported by Mate Marjanović (SharpEdged)

    @xvonfers

    25 Sept 2025

    840 Impressions

    0 Retweets

    7 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-10890 Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium… https://t.co/jAQlXi4pLa

    @CVEnew

    24 Sept 2025

    100 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Chrome CVE-2025-10890 — a side-channel info-leak in Chrome’s V8 engine — is now patched in version 140.0.7339.207/208. Browsers are vulnerable until updated Protect your visitors: 👉 https://t.co/mdVD2iTS3E #Cybersecurity #Infosec #Vulnerability #BrowserSecurity #Threa

    @MNovofastovsky

    24 Sept 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations