CVE-2025-12725Out-of-bounds Read in Google Chrome

CWE-125Out-of-bounds Read8 documents8 sources
Severity
8.8HIGHNVD
EPSS
0.1%
top 75.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10
Latest updateJan 14

Description

Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5google/chrome142.0.7444.137142.0.7444.137
NVDgoogle/chrome< 142.0.7444.137+2
Debianchromium/chromium< 142.0.7444.134-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-4chx-3xpf-9pfj: Out of bounds read in WebGPU in Google Chrome on Android prior to 1422025-11-10
CVEList
CVE-2025-12725: Out of bounds read in WebGPU in Google Chrome on Android prior to 1422025-11-10
OSV
CVE-2025-12725: Out of bounds read in WebGPU in Google Chrome on Android prior to 1422025-11-10

📋Vendor Advisories

4
Palo Alto
PAN-SA-2026-0001 Chromium: Monthly Vulnerability Update (January 2026)2026-01-14
Microsoft
Chromium: CVE-2025-12725 Out of bounds write in WebGPU2025-11-11
Chrome
Stable Channel Update for Desktop: CVE-2025-127252025-11-05
Debian
CVE-2025-12725: chromium - Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137...2025
CVE-2025-12725 — Out-of-bounds Read in Google Chrome | cvebase