CVE-2025-5283
published 2025-05-27CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…
PriorityP428medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.51%
40.3th percentile
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 137.0.7151.55-3~deb12u1 | 137.0.7151.55-3~deb12u1 |
| chromium | chromium | >= 0 < 137.0.7151.55-1 | 137.0.7151.55-1 |
| chromium | chromium | >= 0 < 137.0.7151.55-1 | 137.0.7151.55-1 |
| debian | chromium | < chromium 137.0.7151.55-3~deb12u1 (bookworm) | chromium 137.0.7151.55-3~deb12u1 (bookworm) |
| debian | firefox | < chromium 137.0.7151.55-3~deb12u1 (bookworm) | chromium 137.0.7151.55-3~deb12u1 (bookworm) |
| debian | firefox-esr | < chromium 137.0.7151.55-3~deb12u1 (bookworm) | chromium 137.0.7151.55-3~deb12u1 (bookworm) |
| debian | libvpx | < chromium 137.0.7151.55-3~deb12u1 (bookworm) | chromium 137.0.7151.55-3~deb12u1 (bookworm) |
| debian | thunderbird | < chromium 137.0.7151.55-3~deb12u1 (bookworm) | chromium 137.0.7151.55-3~deb12u1 (bookworm) |
| chrome | < 137.0.7151.55 | 137.0.7151.55 | |
| chrome | >= 137.0.7151.55 < 137.0.7151.55 | 137.0.7151.55 | |
| chrome_chrome | — | — | |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1~deb11u1 | 1:128.11.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1~deb12u1 | 1:128.11.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1 | 1:128.11.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1 | 1:128.11.0esr-1 |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
| webmproject | libvpx | >= 0 < 1.9.0-1+deb11u4 | 1.9.0-1+deb11u4 |
| webmproject | libvpx | >= 0 < 1.12.0-1+deb12u4 | 1.12.0-1+deb12u4 |
| webmproject | libvpx | >= 0 < 1.15.0-2.1 | 1.15.0-2.1 |
| webmproject | libvpx | >= 0 < 1.15.0-2.1 | 1.15.0-2.1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2026-02-02
CVE-2025-8031 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Palo Alto
PAN-SA-2025-0011 Chromium and Prisma Browser: Monthly Vulnerability Update (June 2025)
vendor_paloalto·2025-06-11·CVSS 5.1
[MEDIUM] PAN-SA-2025-0011 Chromium and Prisma Browser: Monthly Vulnerability Update (June 2025)
PAN-SA-2025-0011 Chromium and Prisma Browser: Monthly Vulnerability Update (June 2025)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/05/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html Additionally, a vulnerability in Prisma Browser was also addressed. CVE Summary CVE-2025-4664 Insufficient policy enforcement in Loader CVE-2025-5063 Use after free in Compositing CVE-2025
Ubuntu
libvpx vulnerability
vendor_ubuntu·2025-06-03
CVE-2025-5283 libvpx vulnerability
Title: libvpx vulnerability
Summary: libvpx could be made to crash if it received specially crafted
input.
It was discovered that libvpx did not properly manage memory. An attacker
could possibly use this issue to cause applications using libvpx to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvpx: Double-free in libvpx encoder
vendor_redhat·2025-05-27·CVSS 5.4
CVE-2025-5283 [MEDIUM] CWE-415 libvpx: Double-free in libvpx encoder
libvpx: Double-free in libvpx encoder
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
A flaw was found in libvpx. A double-free issue can occur in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This can cause memory corruption and an exploitable crash.
Statement: This vulnerability marked as Important rather than Moderate due to the nature of the flaw, a double-free in vpx_codec_enc_init_multi, which can lead to heap memory corruption. Double-free issues compromise memory integrity and are often a precursor to use-after-free or arbitrary code execution vulnerabilities, particularly in applications
Chrome
Stable Channel Update for Desktop: CVE-2025-5283
vendor_chrome·2025-05-27·CVSS 5.4
CVE-2025-5283 [MEDIUM] Stable Channel Update for Desktop: CVE-2025-5283
Stable Channel Update for Desktop
CVE-2025-5283: Use after free in libvpx. Reported by Mozilla on 2025-05-22 [$500][ 40075024 ] Low CVE-2025-5067: Inappropriate implementation in Tab Strip
Reported by Khalil Zhani on 2023-10-17 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: medium
Microsoft
Chromium: CVE-2025-5283 Use after free in libvpx
vendor_msrc·2025-05-13·CVSS 5.4
CVE-2025-5283 [MEDIUM] Chromium: CVE-2025-5283 Use after free in libvpx
Chromium: CVE-2025-5283 Use after free in libvpx
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
FAQ: What
Debian
CVE-2025-5283: chromium - Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remot...
vendor_debian·2025·CVSS 5.4
CVE-2025-5283 [MEDIUM] CVE-2025-5283: chromium - Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remot...
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 137.0.7151.55-3~deb12u1)
bullseye: open
forky: resolved (fixed in 137.0.7151.55-1)
sid: resolved (fixed in 137.0.7151.55-1)
trixie: resolved (fixed in 137.0.7151.55-1)
Mozilla
Mozilla Foundation Security Advisory 2025-42: CVE-2025-5283
vendor_mozilla·CVSS 5.4
CVE-2025-5283 [MEDIUM] Mozilla Foundation Security Advisory 2025-42: CVE-2025-5283
Mozilla Foundation Security Advisory 2025-42
CVE: CVE-2025-5283
Product: Firefox
Impact: moderate
Fixed in: Firefox 139
Mozilla
Mozilla Foundation Security Advisory 2025-43: CVE-2025-5283
vendor_mozilla·CVSS 5.4
CVE-2025-5283 [MEDIUM] Mozilla Foundation Security Advisory 2025-43: CVE-2025-5283
Mozilla Foundation Security Advisory 2025-43
CVE: CVE-2025-5283
Product: Firefox ESR
Impact: moderate
Fixed in: Firefox ESR 115.24
Mozilla
Mozilla Foundation Security Advisory 2025-46: CVE-2025-5283
vendor_mozilla·CVSS 5.4
CVE-2025-5283 [MEDIUM] Mozilla Foundation Security Advisory 2025-46: CVE-2025-5283
Mozilla Foundation Security Advisory 2025-46
CVE: CVE-2025-5283
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 128.11
Mozilla
Mozilla Foundation Security Advisory 2025-44: CVE-2025-5283
vendor_mozilla·CVSS 5.4
CVE-2025-5283 [MEDIUM] Mozilla Foundation Security Advisory 2025-44: CVE-2025-5283
Mozilla Foundation Security Advisory 2025-44
CVE: CVE-2025-5283
Product: Firefox ESR
Impact: moderate
Fixed in: Firefox ESR 128.11
Mozilla
Mozilla Foundation Security Advisory 2025-45: CVE-2025-5283
vendor_mozilla·CVSS 5.4
CVE-2025-5283 [MEDIUM] Mozilla Foundation Security Advisory 2025-45: CVE-2025-5283
Mozilla Foundation Security Advisory 2025-45
CVE: CVE-2025-5283
Product: Thunderbird
Impact: moderate
Fixed in: Thunderbird 139
GHSA
GHSA-j84v-78j2-55gh: Use after free in libvpx in Google Chrome prior to 137
ghsa_unreviewed·2025-05-27
CVE-2025-5283 [MEDIUM] CWE-416 GHSA-j84v-78j2-55gh: Use after free in libvpx in Google Chrome prior to 137
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137
osv·2025-05-27·CVSS 5.4
CVE-2025-5283 [MEDIUM] CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_27.htmlhttps://issues.chromium.org/issues/419467315https://lists.debian.org/debian-lts-announce/2025/05/msg00043.htmlhttps://lists.debian.org/debian-lts-announce/2025/05/msg00046.htmlhttps://lists.debian.org/debian-lts-announce/2025/05/msg00052.html
2025-05-27
Published