CVE-2025-10891PoC(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-02); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-01: 1Mentions · 2026-03-02: 2Mentions · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-01: 1PoC Mentioned / Linked · 2026-03-02: 1Exploit Tool / Code · 2026-03-01: 1Technical Details · 2026-03-02: 103-0103-0203-09
Signal classification3 categories
PoC
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-011
PoC1
2026-03-022
General1PoC1
2026-03-091
Disclosure1
Full discourse4 posts
  • m411k@m411k_
    PoC

    Here is my CVE-2025-10891 Chromium RCE PoC: https://github.com/mwlik/v8-ndays/blob/main/CVE-2025-10891/poc.html https://t.co/NtAfSeQtFj

    Post summary

    A Proof of Concept demonstrating a Chromium Remote Code Execution (CVE-2025-10891) is made available through a GitHub repository.

    7104257629130.2K
    480 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Google ❗ CVE-2025-10892 ❗ CVE-2025-10891 ❗ CVE-2025-10890 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-google-4/ https://t.co/7Ksuz7uMHi

    Post summary

    The post announces three new Google product CVEs and links to additional information, but does not provide supporting technical or exploit details.

    01051231
    6.6K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-27363 2 - CVE-2026-21509 3 - CVE-2026-25253 4 - CVE-2025-10891 5 - CVE-2025-64328 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple list of five trending CVEs with no additional context or details.

    00010187
    1.7K followersView on X
  • VulnTracker@vuln_tracker
    PoC

    @m411k_ Chromium RCE via V8 — PoC already public means the clock is ticking for anyone on unpatched Chrome/Edge/Brave. CVE-2025-10891 details + affected versions: http://vulntracker.io/cves/CVE-2025-10891

    Post summary

    A proof‑of‑concept for CVE‑2025‑10891 is publicly available, indicating a remote code execution vulnerability in Chromium via V8, but no active exploitation or patch information is mentioned.

    00001465
    361 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more