CVE-2025-10201Improper Access Control in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.0%
top 93.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateOct 10

Description

Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5google/chrome140.0.7339.127140.0.7339.127
NVDgoogle/chrome< 140.0.7339.127
Debianchromium/chromium< 140.0.7339.127-1~deb12u1+2

🔴Vulnerability Details

3
OSV
CVE-2025-10201: Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 1402025-09-10
CVEList
CVE-2025-10201: Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 1402025-09-10
GHSA
GHSA-fq52-757j-7h2p: Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 1402025-09-10

📋Vendor Advisories

4
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-102012025-10-10
Palo Alto
PAN-SA-2025-0016 Chromium: Monthly Vulnerability Update (October 2025)2025-10-08
Microsoft
Chromium: CVE-2025-10201 Inappropriate implementation in Mojo2025-09-09
Debian
CVE-2025-10201: chromium - Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeO...2025
CVE-2025-10201 — Improper Access Control in Google | cvebase