CVE-2025-0445Use After Free in Google Chrome

CWE-416Use After Free9 documents9 sources
Severity
5.4MEDIUMNVD
EPSS
0.0%
top 84.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateFeb 21

Description

Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages4 packages

CVEListV5google/chrome133.0.6943.53133.0.6943.53
NVDgoogle/chrome< 133.0.6943.53
Debianchromium/chromium< 133.0.6943.53-1~deb12u1+2

🔴Vulnerability Details

3
OSV
CVE-2025-0445: Use after free in V8 in Google Chrome prior to 1332025-02-04
GHSA
GHSA-q4fq-38gr-ccp3: Use after free in V8 in Google Chrome prior to 1332025-02-04
CVEList
CVE-2025-0445: Use after free in V8 in Google Chrome prior to 1332025-02-04

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex - M133: CVE-2025-04452025-02-21
Palo Alto
PAN-SA-2025-0004 Chromium: Monthly Vulnerability Update (February 2025)2025-02-12
Microsoft
Chromium: CVE-2025-0445 Use after free in V82025-02-11
Debian
CVE-2025-0445: chromium - Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote at...2025

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws2025-02-11
CVE-2025-0445 — Use After Free in Google Chrome | cvebase