<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Chrome (&lt; 140.0.7339.185) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/chrome--140.0.7339.185/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 04:52:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/chrome--140.0.7339.185/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Chromium ANGLE Component Heap Buffer Overflow (CVE-2025-10502)</title><link>https://feed.craftedsignal.io/briefs/2026-10-chromium-angle-overflow/</link><pubDate>Sun, 04 Oct 2026 04:52:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-chromium-angle-overflow/</guid><description>CVE-2025-10502 is a heap buffer overflow vulnerability in the Chromium ANGLE graphics engine that could allow an attacker to trigger memory corruption or achieve arbitrary code execution via a malicious webpage.</description><content:encoded><![CDATA[<p>CVE-2025-10502 identifies a heap buffer overflow vulnerability residing within the ANGLE (Almost Native Graphics Layer Engine) component of the Chromium project. ANGLE is used by Chromium-based browsers to translate OpenGL ES calls into underlying graphics APIs such as Direct3D or Metal. This vulnerability is significant because heap buffer overflows in graphics rendering engines often provide a pathway for remote code execution (RCE) if an attacker can successfully manipulate the browser rendering process memory. Because this engine is deeply integrated into the browser's execution pipeline, processing maliciously crafted graphics data can lead to memory corruption, potentially crashing the rendering process or facilitating sandbox escape in specific configurations. Defenders should prioritize updating any Chromium-based applications to the latest security patch provided by the vendor.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to cause an application crash or potentially execute arbitrary code within the context of the user's browser. If exploited, it could result in full browser compromise, sensitive data exfiltration from the browser's memory space, or further lateral movement into the host system. This vulnerability affects all Chromium-based browsers on Windows, macOS, and Linux platforms.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the deployment of vendor-supplied browser updates across all endpoint assets. Monitor for anomalous browser process crashes or unusual activity emanating from web-rendering sub-processes (often labeled as 'renderer' or 'gpu' processes) which may indicate exploitation attempts.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>browser-security</category><category>remote-code-execution</category></item></channel></rss>