Palo Alto 安全中心 07月10日 00:06
PAN-SA-2025-0013 Chromium: Monthly Vulnerability Update (July 2025) (Severity: HIGH)
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Palo Alto Networks发布Chromium安全更新,修复多个高危漏洞,建议用户及时更新。
Palo Alto Networks Security Advisories

/

PAN-SA-2025-0013

PAN-SA-2025-0013 Chromium: Monthly Vulnerability Update (July 2025)

Exploit MaturityATTACKED

Response EffortMODERATE

RecoveryUSER

Value DensityDIFFUSE

Attack VectorNETWORK

Attack ComplexityLOW

Attack RequirementsNONE

AutomatableNO

User InteractionACTIVE

Product ConfidentialityHIGH

Product IntegrityHIGH

Product AvailabilityHIGH

Privileges RequiredNONE

Subsequent ConfidentialityNONE

Subsequent IntegrityNONE

Subsequent AvailabilityNONE

Description

Palo Alto Networks incorporated the following Chromium security fixes into our products:
CVESummary
CVE-2025-5958Use after free in Media
CVE-2025-5959Type Confusion in V8
CVE-2025-6191Integer overflow in V8
CVE-2025-6192Use after free in Metrics
CVE-2025-6554Type confusion in V8
CVE-2025-6555Use after free in Animation
CVE-2025-6556Insufficient policy enforcement in Loader
CVE-2025-6557Insufficient data validation in DevTools

Product Status

Required Configuration for Exposure

No special configuration is required to be affected by this issue.

Severity:HIGH, Suggested Urgency:MODERATE

CVSS-BT:8.6 /CVSS-B:8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:N/R:U/V:D/RE:M/U:Amber)

Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Solution

CVEPrisma Access Browser
CVE-2025-5958
137.16.6.120
CVE-2025-5959
137.16.6.120
CVE-2025-6191
137.27.4.120
CVE-2025-6192
137.27.4.120
CVE-2025-6554
138.33.5.97
CVE-2025-6555
138.33.5.97
CVE-2025-6556
138.33.5.97
CVE-2025-6557
138.33.5.97

Workarounds and Mitigations

No workaround or mitigation is available.

CPE Applicability

  • cpe:2.3:a:palo_alto_networks:prisma_access_browser:*:*:*:*:*:*:*:* is vulnerable from (including)137.16.2 and up to (excluding)137.16.2.69

Timeline

Initial publication

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Palo Alto Networks Chromium 安全更新 漏洞修复 高危漏洞
相关文章