CVE-2025-14765Use After Free in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.1%
top 68.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateDec 17

Description

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome143.0.7499.147143.0.7499.147
NVDgoogle/chrome< 143.0.7499.146
Debianchromium/chromium< 143.0.7499.169-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-gv8f-9g4r-fj8q: Use after free in WebGPU in Google Chrome prior to 1432025-12-17
CVEList
CVE-2025-14765: Use after free in WebGPU in Google Chrome prior to 1432025-12-16
OSV
CVE-2025-14765: Use after free in WebGPU in Google Chrome prior to 1432025-12-16

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-147652025-12-17
Red Hat
chromium-browser: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption2025-12-16
Microsoft
Chromium: CVE-2025-14765 Out of bounds read and write in V82025-12-09
Debian
CVE-2025-14765: chromium - Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remo...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-14765 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-14765 — Use After Free in Google Chrome | cvebase