CVE-2025-14766Out-of-bounds Read in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.1%
top 72.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateDec 17

Description

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome143.0.7499.147143.0.7499.147
NVDgoogle/chrome< 143.0.7499.146
Debianchromium/chromium< 143.0.7499.169-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-r5qp-7h29-v42w: Out of bounds read and write in V8 in Google Chrome prior to 1432025-12-17
CVEList
CVE-2025-14766: Out of bounds read and write in V8 in Google Chrome prior to 1432025-12-16
OSV
CVE-2025-14766: Out of bounds read and write in V8 in Google Chrome prior to 1432025-12-16

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-147662025-12-17
Red Hat
chromium-browser: Google Chrome V8: Out-of-bounds read and write leads to heap corruption2025-12-16
Microsoft
Chromium: CVE-2025-14766 Use after free in WebGPU2025-12-09
Debian
CVE-2025-14766: chromium - Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allo...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-14766 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-14766 — Out-of-bounds Read in Google Chrome | cvebase