CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-10890

CVSS 9.1v3.1pub. 2025-09-24upd. 2025-09-25

Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

🤖 AI Analysis
How it works

The vulnerability consists of information leakage through a side-channel in the V8 engine. An attacker is able to read data belonging to other origins (cross-origin), which constitutes a violation of the same-origin policy. The mechanism is based on observing differences in timing or resource behavior of the JavaScript engine (CWE-203: Observable Discrepancy), which allows inferring the contents of data that is not directly accessible. It is sufficient for the victim to visit a malicious HTML page prepared by the attacker.

Impact

An attacker may gain access to sensitive data belonging to other websites (cross-origin), such as session tokens, credentials, or other sensitive information processed by the browser. Data integrity is not directly threatened, however the confidentiality breach may lead to further attacks.

Mitigation & patch

Google Chrome should be updated to version 140.0.7339.207 or newer. The update is available through the browser's built-in update mechanism or directly from the vendor's website (chromereleases.googleblog.com).

Who is affected

Google Chrome in versions earlier than 140.0.7339.207 on Microsoft Windows, Linux, and Apple macOS systems.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apple macOS

    OS
    Apple
    all versions
  • Google Chrome

    APP
    Google
    < 140.0.7339.207
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP