CVE-2025-10201 — Improper Access Control in Google Chrome
Severity
8.8HIGHNVD
EPSS
0.0%
top 93.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 10
Latest updateOct 10
Description
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
3OSV▶
CVE-2025-10201: Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140↗2025-09-10
CVEList▶
CVE-2025-10201: Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140↗2025-09-10
GHSA▶
GHSA-fq52-757j-7h2p: Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140↗2025-09-10
📋Vendor Advisories
4Debian▶
CVE-2025-10201: chromium - Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeO...↗2025