SB2025080602 - Multiple vulnerabilities in Google Chrome
Published: August 6, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 secuirty vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2025-8576)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Extensions in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
2) Improperly implemented security check for standard (CVE-ID: CVE-2025-8577)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Picture In Picture in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
3) Use-after-free (CVE-ID: CVE-2025-8578)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Cast in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
4) Improperly implemented security check for standard (CVE-ID: CVE-2025-8579)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Gemini Live in Chrome in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
5) Improperly implemented security check for standard (CVE-ID: CVE-2025-8580)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Filesystems in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
6) Improperly implemented security check for standard (CVE-ID: CVE-2025-8581)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Extensions in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
7) Input validation error (CVE-ID: CVE-2025-8582)
The vulnerability allows a remote attacker to gain access to crash the browser.
The vulnerability exists due to a improper input validation in DOM in Google Chrome. A remote attacker can trick the victim to perform certain actions in browser and crash it.
8) Improperly implemented security check for standard (CVE-ID: CVE-2025-8583)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Permissions in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop.html
- https://crbug.com/414760982
- https://crbug.com/384050903
- https://crbug.com/423387026
- https://crbug.com/407791462
- https://crbug.com/411544197
- https://crbug.com/416942878
- https://crbug.com/40089450
- https://crbug.com/373794472