Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14765

Опубликовано: 16 дек. 2025
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Chromium (Google Chrome). This vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML (HyperText Markup Language) page due to a use after free in WebGPU (Web Graphics Processing Unit).

Отчет

This vulnerability is rated Important for Red Hat due to a use-after-free flaw in WebGPU within chromium-browser. A remote attacker could exploit heap corruption by enticing a user to visit a crafted HTML page, potentially leading to arbitrary code execution in the context of the browser.

Меры по смягчению последствий

To mitigate this issue, users should avoid visiting untrusted websites or opening untrusted HTML content. Employing a robust web browser sandbox, if available and configured, can further limit the potential impact of successful exploitation.

Дополнительная информация

Статус:

Important
Дефект:
CWE-763
https://bugzilla.redhat.com/show_bug.cgi?id=2422949chromium-browser: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption

EPSS

Процентиль: 32%
0.00127
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

msrc
4 месяца назад

Chromium: CVE-2025-14765 Out of bounds read and write in V8

CVSS3: 8.8
debian
4 месяца назад

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allo ...

CVSS3: 8.8
github
4 месяца назад

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
fstec
4 месяца назад

Уязвимость компонента WebGPU браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 32%
0.00127
Низкий

8.8 High

CVSS3