CVE-2025-0444Use After Free in Google Chrome

CWE-416Use After Free10 documents9 sources
Severity
6.3MEDIUMNVD
OSV8.8
EPSS
0.2%
top 62.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateJun 5

Description

Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages4 packages

CVEListV5google/chrome133.0.6943.53133.0.6943.53
NVDgoogle/chrome< 133.0.6943.53
Debianchromium/chromium< 133.0.6943.53-1~deb12u1+2

🔴Vulnerability Details

4
OSV
gst-plugins-bad1.0 vulnerabilities2025-06-05
CVEList
CVE-2025-0444: Use after free in Skia in Google Chrome prior to 1332025-02-04
OSV
CVE-2025-0444: Use after free in Skia in Google Chrome prior to 1332025-02-04
GHSA
GHSA-g9q6-f2j4-7cvg: Use after free in Skia in Google Chrome prior to 1332025-02-04

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex - M133: CVE-2025-04442025-02-21
Palo Alto
PAN-SA-2025-0004 Chromium: Monthly Vulnerability Update (February 2025)2025-02-12
Microsoft
Chromium: CVE-2025-0444 Use after free in Skia2025-02-11
Debian
CVE-2025-0444: chromium - Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote ...2025

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws2025-02-11
CVE-2025-0444 — Use After Free in Google Chrome | cvebase