Google released Chrome fixes for multiple high-severity vulnerabilities in the V8 JavaScript engine, including CVE-2025-10891, CVE-2025-10892, and CVE-2025-9864, that could be triggered when a user visits a malicious web page. The flaws include integer overflows and a use-after-free condition that can cause heap corruption in the browser renderer and potentially lead to arbitrary code execution. A related bulletin also lists CVE-2025-10890, a V8 side-channel information disclosure issue, alongside the two integer overflow bugs, warning that successful exploitation could expose sensitive data or enable full system compromise.
Google said the affected Chrome builds were patched across Windows, macOS, and Linux in the 140.0.7339 release line, with fixes landing in versions including 140.0.7339.80/.81 and later 140.0.7339.207/.208 depending on the flaw and platform. Several of the vulnerabilities were reportedly identified by Google’s AI-based Big Sleep system, and no public proof-of-concept exploits were cited in the referenced reports. Organizations using Chrome or Chromium-based browsers were urged to deploy the vendor updates promptly because the bugs are reachable through routine web browsing and may also affect downstream browsers that have not yet incorporated the upstream patches.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A bulletin described three Google Chrome V8 vulnerabilities: CVE-2025-10890, CVE-2025-10891, and CVE-2025-10892. It states CVE-2025-10890 enables information disclosure and the other two integer overflow flaws can allow remote code execution, and recommends applying the vendor update.
Google fixed high-severity integer overflow vulnerabilities CVE-2025-10891 and CVE-2025-10892 in Chrome's V8 JavaScript engine in version 140.0.7339.207/.208. The flaws could allow heap corruption and potentially arbitrary code execution when a victim visits a malicious web page, and the content says they were discovered by Google's Big Sleep system.
Google patched CVE-2025-10502, a heap buffer overflow in Chrome's ANGLE graphics engine, by adding stricter bounds checking. The flaw affected Chrome on Windows, macOS, and Linux before versions 140.0.7339.185 or 140.0.7339.186 depending on platform.
Google's September 2025 Android Security Bulletin addressed CVE-2025-32320, a local privilege escalation flaw in Android 16 System UI that could let attackers access images belonging to other users on a shared device. The content states affected devices are those prior to security patch level 2025-09-05.
Google made fixes available for CVE-2025-9864, a high-severity use-after-free vulnerability in Chrome's V8 engine that could be triggered via a malicious web page. The patched versions are Chrome 140.0.7339.80 for Linux and 140.0.7339.80/.81 for Windows and Mac.
Google addressed CVE-2025-32318, a critical heap-based buffer overflow in the Skia graphics engine, through Android 16 System component patches integrated into AOSP. The content says users should update to security patch level 2025-07-01 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecurity-help.cz
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.