CVE-2025-10201 is a high-severity vulnerability in Google Chrome on Android, Linux, and ChromeOS, affecting versions prior to 140.0.7339.127. This inappropriate implementation in Mojo allows a remote attacker to bypass site isolation through a crafted HTML page. With a CVSS score of 8.8, the vulnerability has a high impact on confidentiality, integrity, and availability, requiring user interaction but no prior authentication. While not currently listed in CISA's KEV catalog, it has garnered some community discussion and media coverage, including a reported $43,000 bounty for its discovery. There is no public exploit code available via Metasploit, Nuclei, or ExploitDB, and it is not considered actively exploited at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.0.7339.127CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 140.0.7339.127, < 140.0.7339.127CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.