CVE-2025-10890
No sign of exploitation. No public exploitation artifact known so far.
A flaw in Chrome's V8 engine allows attackers to steal private data from other websites you visit by sending you a specially crafted web page. This breaks the browser's security boundaries that normally keep websites isolated from each other.
CVE-2025-10890 exploits a side-channel vulnerability in V8's implementation that enables cross-origin data exfiltration through timing or behavioral analysis triggered by a malicious HTML page. The attack requires user interaction (visiting the crafted page) and leverages information leakage from cache or execution patterns to bypass same-origin policy protections. Impact includes unauthorized disclosure of sensitive data from other origins.