CVE-2025-9864 Details
Description
Rejected reason: This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code landed in the Stable channel of Chrome, and has been withdrawn.
A use-after-free vulnerability has been identified in the V8 JavaScript engine used by Google Chrome. This issue affects Chrome versions prior to 140.0.7339.80. The vulnerability could allow a remote attacker to exploit heap corruption by sending a crafted HTML page.
Users can update to Google Chrome version 140.0.7339.80 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Nov 13, 2025 | CVE Rejected | [email protected] |
| Nov 13, 2025 | CVE Modified | [email protected] |
| Sep 4, 2025 | Initial Analysis | [email protected] |
| Sep 3, 2025 | New CVE Received | [email protected] |
| Sep 3, 2025 | CVE Modified | CISA-ADP |