CVE-2025-12438 — Use After Free in Google Chrome
Severity
8.8HIGHNVD
EPSS
0.1%
top 74.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 10
Latest updateNov 12
Description
Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: Medium)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
3OSV▶
CVE-2025-12438: Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142↗2025-11-10
CVEList▶
CVE-2025-12438: Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142↗2025-11-10
GHSA▶
GHSA-4w9w-65jx-4742: Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142↗2025-11-10