CVE-2025-12428 is a high-severity type confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting various operating systems including Apple, Google, Linux, and Microsoft. A remote attacker can exploit this flaw by tricking a user into visiting a crafted HTML page, leading to arbitrary read/write capabilities. With a CVSS score of 8.8, this vulnerability poses a significant risk of high impact to confidentiality, integrity, and availability. While there is no known public exploit code or active exploitation in the wild, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 142.0.7444.59CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 142.0.7444.59, < 142.0.7444.59CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.