{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/chrome--140.0.7339.185/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2025-10502"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Chrome (\u003c 140.0.7339.185)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","browser-security","remote-code-execution"],"_cs_type":"threat","_cs_vendors":["Google"],"content_html":"\u003cp\u003eCVE-2025-10502 identifies a heap buffer overflow vulnerability residing within the ANGLE (Almost Native Graphics Layer Engine) component of the Chromium project. ANGLE is used by Chromium-based browsers to translate OpenGL ES calls into underlying graphics APIs such as Direct3D or Metal. This vulnerability is significant because heap buffer overflows in graphics rendering engines often provide a pathway for remote code execution (RCE) if an attacker can successfully manipulate the browser rendering process memory. Because this engine is deeply integrated into the browser's execution pipeline, processing maliciously crafted graphics data can lead to memory corruption, potentially crashing the rendering process or facilitating sandbox escape in specific configurations. Defenders should prioritize updating any Chromium-based applications to the latest security patch provided by the vendor.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to cause an application crash or potentially execute arbitrary code within the context of the user's browser. If exploited, it could result in full browser compromise, sensitive data exfiltration from the browser's memory space, or further lateral movement into the host system. This vulnerability affects all Chromium-based browsers on Windows, macOS, and Linux platforms.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the deployment of vendor-supplied browser updates across all endpoint assets. Monitor for anomalous browser process crashes or unusual activity emanating from web-rendering sub-processes (often labeled as 'renderer' or 'gpu' processes) which may indicate exploitation attempts.\u003c/p\u003e\n","date_modified":"2026-10-04T04:52:58Z","date_published":"2026-10-04T04:52:58Z","id":"https://feed.craftedsignal.io/briefs/2026-10-chromium-angle-overflow/","summary":"CVE-2025-10502 is a heap buffer overflow vulnerability in the Chromium ANGLE graphics engine that could allow an attacker to trigger memory corruption or achieve arbitrary code execution via a malicious webpage.","title":"Chromium ANGLE Component Heap Buffer Overflow (CVE-2025-10502)","url":"https://feed.craftedsignal.io/briefs/2026-10-chromium-angle-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Chrome (\u003c 140.0.7339.185)","version":"https://jsonfeed.org/version/1.1"}