Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields.
Link | Tags |
---|---|
https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html | release notes |
https://issues.chromium.org/issues/425583995 | permissions required issue tracking |