Chromium Security Update (MINDBREEZE33815)

ID: MINDBREEZE33815 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 6.8 Medium 
Status: Final 
CVEs: CVE-2024-11395, CVE-2024-12053, CVE-2024-12381, CVE-2024-12692, CVE-2024-12693, CVE-2024-12694, CVE-2024-12695, CVE-2025-0434, CVE-2025-0435, CVE-2025-0436, CVE-2025-0437, CVE-2025-0438, CVE-2025-0439, CVE-2025-0441, CVE-2025-0442, CVE-2025-0447, CVE-2025-0448, CVE-2025-0291, CVE-2025-0611, CVE-2025-0612 

Summary 

  • chromium - Component: Type Confusion in V8.
  • chromium - Component: Out of bounds memory access in V8.
  • chromium - Component: Use after free in Compositing.
  • chromium - Component: Out of bounds write in V8.
  • chromium - Component: Inappropriate implementation in Navigation.
  • chromium - Component: Integer overflow in Skia.
  • chromium - Component: Out of bounds read in Metrics.
  • chromium - Component: Stack buffer overflow in Tracing.
  • chromium - Component: Race in Frames.
  • chromium - Component: Inappropriate implementation in Fenced Frames.
  • chromium - Component: Inappropriate implementation in Payments.
  • chromium - Component: Inappropriate implementation in Navigation.
  • chromium - Component: Inappropriate implementation in Compositing.
  • chromium - Component: Object corruption in V8. 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 25.1 Release
  • Mindbreeze InSpire Saas 25.1 Release