CVE-2025-12036

Published Nov 6, 2025

Last updated 16 hours ago

Overview

Description
Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Source
chrome-cve-admin@google.com
NVD status
Analyzed
Products
chrome

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-125

Social media

Hype score
Not currently trending
  1. URGENT: #openSUSE Leap 16.0 users must patch Chromium for CVE-2025-12036. This V8 engine flaw is a serious threat. Patch now via YaST or zypper. Read more: 👉 https://t.co/cOOayZS9om #Security https://t.co/JKdiZArBWM

    @Cezar_H_Linux

    11 Nov 2025

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. URGENT: #Fedora 43 security update for CEF is live! 🔒 Patches HIGH-severity flaws: CVE-2025-12036 (V8), CVE-2025-11756 (Safe Browsing), and more. Remote code execution risk. Read mroe: 👉 https://t.co/K9WaMlFmfD #Security https://t.co/79oDmFVES3

    @Cezar_H_Linux

    11 Nov 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-12036 Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (… https://t.co/IKutCwC916

    @CVEnew

    6 Nov 2025

    229 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-12036 es una vulnerabilidad que permite la ejecución remota de código (RCE) que se deriva de una implementación inapropiada dentro del motor JavaScript y WebAssembly V8. Mas información: https://t.co/niB4heFTR8 #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @Csir

    @EcuCERT_EC

    31 Oct 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. گوگل نے کروم براؤزر میں سنگین سیکیورٹی خامی دور کرنے کیلئے ایک اور ہنگامی اپ ڈیٹ جاری کر دی۔ یہ بگ (CVE-2025-12036) صارفین کے سسٹم کو ریموٹ کوڈ حملوں کے خطرے میں ڈا

    @pak2050_2050

    26 Oct 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. گوگل نے کروم براؤزر میں سنگین سیکیورٹی خامی دور کرنے کیلئے ایک اور ہنگامی اپ ڈیٹ جاری کر دی۔ یہ بگ (CVE-2025-12036) صارفین کے سسٹم کو ریموٹ کوڈ حملوں کے خطرے میں ڈا

    @VisionPointPK

    26 Oct 2025

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. A single visit could’ve exposed billions; update Chrome now and shut the door on CVE-2025-12036. #computertips #technology #techtips #JENI https://t.co/aarlN5xLCa https://t.co/3JDx2GIbL6

    @JeniSystems

    24 Oct 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. URGENT: #openSUSE Security Update for #Chromium is live! Patch CVE-2025-12036, a critical V8 engine flaw that could lead to remote code execution. Read more: 👉 https://t.co/e3e32S7cmt https://t.co/Ukb0w2zmoj

    @Cezar_H_Linux

    24 Oct 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 Google has issued an urgent Chrome update patching a high-severity flaw (CVE-2025-12036) in the V8 JavaScript engine. Discovered by the AI-driven Big Sleep project, the bug could allow remote code execution on unpatched systems. Update to Chrome 141.0.7390.122+ ASAP.

    @packtwebdevpro

    24 Oct 2025

    97 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Google、Chrome 141 V8 の高危険度 脆弱性(CVE-2025-12036)を修正 https://t.co/em5UGcoNrO #セキュリティ対策Lab #セキュリティ #Security

    @securityLab_jp

    23 Oct 2025

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Windows、Mac、Linux、Androidの各エコシステムでChromeウェブブラウザーを利用する35億人のユーザーの1人なら、グーグルが1週間のうちに2度目となる緊急のセキュリティアップデートを公開したことに注意を払う必

    @DieZeitDrangte

    23 Oct 2025

    125 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 「CVE-2025-12036」の要点と、未適用のユーザーがリモートからのコード実行攻撃にさらされ得る状況から身を守る方法を示す →今すぐ対応を──グーグルが35億人のChromeユーザーに向け新たな緊急アップデート

    @forbesjapan

    23 Oct 2025

    750 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. (CVE-2025-12036)[452296415][json][Parser]Expect()/ExpectNext() used to simply set the cursor to the end of the input if the failed expectation, can trigger a GC due to allocation of the Exception object https://t.co/y1jjfYfJne https://t.co/2WcQCQg6Lq Reported by Google Big Sleep

    @xvonfers

    22 Oct 2025

    1263 Impressions

    0 Retweets

    13 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  14. The single-issue security updates are coming so thick and fast at the moment that Google is thinking of changing the name from Chrome to the London Omnibus Browser. Kudos to Big Sleep for uncovering CVE-2025-12036 though. #Infosec https://t.co/KUPOLlq9Uw

    @happygeek

    22 Oct 2025

    179 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. A critical flaw (CVE-2025-12036) in Chrome’s V8 JavaScript engine lets attackers run code remotely — just by getting you to visit a malicious site. 🌐 https://t.co/9oiMoRejfD https://t.co/057AKR8g8D

    @Zoffecinfotech

    22 Oct 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🇺🇸 🚨 BREAKING: Google issues emergency Chrome update to patch high-severity V8 JS vuln CVE-2025-12036 after internal AI-driven discovery. Global RCE risk — update Chrome now. #Cybersecurity #OSINT https://t.co/1OCKp2Y0Bb

    @STRATINT_AI

    22 Oct 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Google issued an urgent Stable Channel update for Chrome (v141.0.7390.122) to fix a High-severity V8 flaw (CVE-2025-12036) that could lead to Remote Code Execution via a malicious web page. #ChromeUpdate #V8Engine #Cybersecurity #PatchNow https://t.co/e6XFd6KDtZ

    @the_yellow_fall

    22 Oct 2025

    429 Impressions

    5 Retweets

    5 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

Configurations