AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-2509

HIGH · CVSS 7.8 EPSS 0.11%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-05-06 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Chrome.

CVE
CVE-2025-2509
Severity
HIGH
CVSS
7.8
EPSS
0.11%
Chrome

Original NVD Description

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.

Related CVEs

Other vulnerabilities affecting the same vendor(s)