Insecure GitHub Actions Expose Critical MITRE And Splunk Flaws
June 18, 2025Multiple Dell Products Vulnerabilities
June 18, 2025Insecure GitHub Actions Expose Critical MITRE And Splunk Flaws
June 18, 2025Multiple Dell Products Vulnerabilities
June 18, 2025Severity
High
Analysis Summary
CVE-2025-6192 CVSS:8.8
A use-after-free vulnerability in the Profiler component of Google Chrome, Use-after-free vulnerabilities can allow attackers to execute arbitrary code by exploiting memory management errors. Potential impacts include remote code execution, system compromise, or unauthorized access to sensitive system resources
CVE-2025-6191 CVSS:8.8
Integer overflow vulnerability in the V8 JavaScript engine of Google Chrome could potentially allow attackers to execute arbitrary code or cause unexpected behavior in the Chrome browser. This type of vulnerability can be exploited to crash the application or potentially run malicious code within the context of the browser.
Impact
- Code Execution
Indicators of Compromise
CVE
CVE-2025-6192
CVE-2025-6191
Affected Vendors
Affected Products
- Google Chrome to version 137.0.7151.119 or late
Remediation
Upgrade to the latest version of Google Chrome, available from the Google Chrome Releases Website.