CVE-2025-9864
Google Chrome V8 Use-After-Free Vulnerability
Description
Rejected reason: This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code landed in the Stable channel of Chrome, and has been withdrawn.
INFO
Published Date :
Sept. 3, 2025, 5:15 p.m.
Last Modified :
Nov. 13, 2025, 6:15 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
Solution
- Update Google Chrome to the latest version.
- Ensure the browser is updated to version 140.0.7339.80 or later.
Public PoC/Exploit Available at Github
CVE-2025-9864 has a 1 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
EPSS & VEDAS Score Aggregator for CVEs
cve vulnerability exploit epss vedas exploit-maturity
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-9864 vulnerability anywhere in the article.
-
BleepingComputer
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
Today is Microsoft's September 2025 Patch Tuesday, which includes security updates for 81 flaws, including two publicly disclosed zero-day vulnerabilities. This Patch Tuesday also fixes nine "Critical ... Read more
The following table lists the changes that have been made to the
CVE-2025-9864 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Rejected by [email protected]
Nov. 13, 2025
Action Type Old Value New Value -
CVE Modified by [email protected]
Nov. 13, 2025
Action Type Old Value New Value Changed Description Use after free in V8 in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Rejected reason: This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code landed in the Stable channel of Chrome, and has been withdrawn. Removed CVSS V3.1 CISA-ADP: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Removed CWE Chrome: CWE-416 Removed CPE Configuration OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 140.0.7339.80 Removed Reference Chrome: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.html Removed Reference Chrome: https://issues.chromium.org/issues/434513380 Removed Reference Type Chrome: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.html Types: Release Notes Removed Reference Type Chrome: https://issues.chromium.org/issues/434513380 Types: Issue Tracking, Permissions Required -
Initial Analysis by [email protected]
Sep. 04, 2025
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 140.0.7339.80 Added Reference Type Chrome: https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.html Types: Release Notes Added Reference Type Chrome: https://issues.chromium.org/issues/434513380 Types: Issue Tracking, Permissions Required -
New CVE Received by [email protected]
Sep. 03, 2025
Action Type Old Value New Value Added Description Use after free in V8 in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Added CWE CWE-416 Added Reference https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.html Added Reference https://issues.chromium.org/issues/434513380 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Sep. 03, 2025
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H