CVE-2025-14372Use After Free in Google Chrome

CWE-416Use After Free8 documents7 sources
Severity
6.1MEDIUMNVD
EPSS
0.1%
top 79.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 12
Latest updateDec 17

Description

Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

CVEListV5google/chrome143.0.7499.110143.0.7499.110
NVDgoogle/chrome< 143.0.7499.109
Debianchromium/chromium< 143.0.7499.109-1~deb12u1+2

🔴Vulnerability Details

2
CVEList
CVE-2025-14372: Use after free in Password Manager in Google Chrome prior to 1432025-12-12
OSV
CVE-2025-14372: Use after free in Password Manager in Google Chrome prior to 1432025-12-12

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-143722025-12-17
Chrome
Stable Channel Update for Desktop: CVE-2025-141742025-12-10
Microsoft
Chromium: CVE-2025-14372 Use after free in Password Manager2025-12-09
Debian
CVE-2025-14372: chromium - Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allo...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-14372 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-14372 — Use After Free in Google Chrome | cvebase