CVE-2025-12438Use After Free in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.1%
top 74.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateNov 12

Description

Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5google/chrome142.0.7444.59142.0.7444.59
NVDgoogle/chrome< 142.0.7444.59
Debianchromium/chromium< 142.0.7444.59-1~deb12u1+2

🔴Vulnerability Details

3
OSV
CVE-2025-12438: Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 1422025-11-10
CVEList
CVE-2025-12438: Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 1422025-11-10
GHSA
GHSA-4w9w-65jx-4742: Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 1422025-11-10

📋Vendor Advisories

5
Palo Alto
PAN-SA-2025-0018 Chromium and Prisma Browser: Monthly Vulnerability Update (November 2025)2025-11-12
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-124382025-11-11
Red Hat
chromium-browser: Use after free in Ozone2025-11-10
Microsoft
Chromium: CVE-2025-12438 Use after free in Ozone2025-10-14
Debian
CVE-2025-12438: chromium - Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.74...2025
CVE-2025-12438 — Use After Free in Google Chrome | cvebase