NJRAT – Active IOCs
February 6, 2025Multiple IBM Products Vulnerabilities
February 6, 2025NJRAT – Active IOCs
February 6, 2025Multiple IBM Products Vulnerabilities
February 6, 2025Severity
High
Analysis Summary
CVE-2025-0762 CVSS:8.8
Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
CVE-2025-0611 CVSS:8.8
Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2025-0612 CVSS:8.8
Google Chrome could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds memory access in V8. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
- Code Execution
- Gain Access
Indicators of Compromise
CVE
CVE-2025-0762
CVE-2025-0611
CVE-2025-0612
Affected Vendors
Affected Products
- Google Chrome - 132.0.6834.159
- Google Chrome - 132.0
Remediation
Upgrade to the latest version of Google Chrome, available from the Google Chrome Releases Website.