Welcome Guest Search | Active Topics | Sign In | Register

Vulnerabilities in Chromium based browsers Options
Bjarne Ingelsson
Posted: Friday, March 21, 2025 8:44:10 AM
Rank: Newbie
Groups: Member

Joined: 3/20/2025
Posts: 1
Is the browser control affected by these CVE's, and is so, when can we expect an update?
---
Google Chrome versions prior to 134.0.6998.88 (Linux), 134.0.6998.88/.89 (Windows) and 134.0.6998.88/.89 (Mac)
---
Several vulnerabilities have been fixed in the Google Chrome browser. They allow an unauthenticated remote attacker:to execute arbitrary code,to cause a denial of service,to illegally take knowledge of potentially sensitive data,to compromise data integrity.Note: Google signals they are aware of an exploit for CVE-2025-24201. However, Cert-IST is not aware of any public exploit code.
---
These vulnerabilities are due to:CVE-2025-1920, CVE-2025-2135: type confusion issues in V8 leading to heap memory corruption. They allow an unauthenticated remote attacker, by tricking the user into opening a specially crafted HTML page, to cause a denial of service or execute arbitrary code. CVE-2025-2136: a use-after-free issue in Chromium's developer tools leading to heap memory corruption. It allows an unauthenticated remote attacker, by tricking the user into opening a specially crafted HTML page, to cause a denial of service or execute arbitrary code. CVE-2025-2137: an out-of-bounds read issue in V8. It allows an unauthenticated remote attacker, by tricking the user into opening a specially crafted HTML page, to compromise data confidentiality or cause a denial of service. CVE-2025-24201: an undetailed out-of-bounds write issue in the GPU. It allows an unauthenticated remote attacker to compromise data integrity or cause a denial of service.
---


-: I also have a udp joke, but you might not get it :-
eo_support
Posted: Sunday, March 23, 2025 11:51:08 PM
Rank: Administration
Groups: Administration

Joined: 5/27/2007
Posts: 24,314
Hi,

Our current version is based on Chromium v126. Since this is before v134, it would be affected by these issues. However we do not have a time line on when we can release an update yet because for security purpose, the details and fix for these issues are not public yet. We will need to wait for Google to publicially release both first before we can decide when/how to port the fix into our codebase.

Thanks!


You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.