Skip to content
Threat Feed
high advisory updated

Chromium V8 Engine Object Corruption Vulnerability

CVE-2025-0611 is a high-severity object corruption vulnerability in the Chromium V8 engine that could allow remote arbitrary code execution via a malicious web page.

CVE search metadata

CVE search record: CVE-2025-0611. Severity: high. CVSS: 8.2. EPSS: 0.41%. KEV: no. Product: Chromium (< 132.0.6834.110), Chromium (< 141.0.7390.54). Brief: Chromium V8 Engine Object Corruption Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-chromium-v8-corruption/

CVE search record: CVE-2025-0612. Severity: high. CVSS: 7.5. EPSS: 0.48%. KEV: no. Product: Chromium (< 132.0.6834.110), Chromium (< 141.0.7390.54). Brief: Chromium V8 Engine Object Corruption Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-10-chromium-v8-corruption/

What's new

  • 1. added coverage for Chromium (< 141.0.7390.54) Oct 8, 19:29 via msrc
  • 2. added coverage for Chromium (< 141.0.7390.54) Oct 8, 10:50 via msrc

CVE-2025-0611 is a high-severity object corruption vulnerability identified within the V8 JavaScript engine used in the Chromium web browser. This flaw exists in the memory management logic of the V8 engine, potentially allowing an attacker to corrupt object structures during execution. If successfully exploited, a remote attacker could influence browser memory, leading to potential arbitrary code execution within the context of the user's browser process. Because Chromium serves as the foundational engine for numerous web browsers and desktop applications, the scope of exposure is significant across all platforms where Chromium-based software is deployed. Defenders should prioritize updating browser versions to the latest patch release provided by their specific vendor to mitigate this risk.

Impact

Successful exploitation of CVE-2025-0611 allows remote code execution in the context of the browser process. This provides an attacker the ability to bypass standard browser security sandboxes, potentially leading to unauthorized data access, session theft, or the installation of further payloads on the end-user system. The vulnerability affects all users running vulnerable versions of Chromium-based browsers, making it a critical risk for both enterprise environments and general consumer users.

Recommendation

Prioritize updating all instances of Chromium-based browsers (such as Google Chrome, Microsoft Edge, and Brave) to the latest stable versions that incorporate the upstream fix for CVE-2025-0611. Monitor vendor security update channels for specific release identifiers that address this memory corruption flaw.

Mitigations

Patch Chromium to 132.0.6834.110 or later

immediate IT Operations

CVE-2025-0611