cbcvebase.
CVE-2025-5283
published 2025-05-27

CVE-2025-5283: Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page…

medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Affected

22 ranges
VendorProductVersion rangeFixed in
chromiumchromium>= 0 < 137.0.7151.55-3~deb12u1137.0.7151.55-3~deb12u1
chromiumchromium>= 0 < 137.0.7151.55-1137.0.7151.55-1
chromiumchromium>= 0 < 137.0.7151.55-1137.0.7151.55-1
debianchromium< chromium 137.0.7151.55-3~deb12u1 (bookworm)chromium 137.0.7151.55-3~deb12u1 (bookworm)
debianfirefox< chromium 137.0.7151.55-3~deb12u1 (bookworm)chromium 137.0.7151.55-3~deb12u1 (bookworm)
debianfirefox-esr< chromium 137.0.7151.55-3~deb12u1 (bookworm)chromium 137.0.7151.55-3~deb12u1 (bookworm)
debianlibvpx< chromium 137.0.7151.55-3~deb12u1 (bookworm)chromium 137.0.7151.55-3~deb12u1 (bookworm)
debianthunderbird< chromium 137.0.7151.55-3~deb12u1 (bookworm)chromium 137.0.7151.55-3~deb12u1 (bookworm)
googlechrome< 137.0.7151.55137.0.7151.55
googlechrome>= 137.0.7151.55 < 137.0.7151.55137.0.7151.55
googlechrome_chrome
mozillafirefox
mozillathunderbird>= 0 < 1:128.11.0esr-1~deb11u11:128.11.0esr-1~deb11u1
mozillathunderbird>= 0 < 1:128.11.0esr-1~deb12u11:128.11.0esr-1~deb12u1
mozillathunderbird>= 0 < 1:128.11.0esr-11:128.11.0esr-1
mozillathunderbird>= 0 < 1:128.11.0esr-11:128.11.0esr-1
msrcmicrosoft_edge
paloaltoprisma_browser
webmprojectlibvpx>= 0 < 1.9.0-1+deb11u41.9.0-1+deb11u4
webmprojectlibvpx>= 0 < 1.12.0-1+deb12u41.12.0-1+deb12u4
webmprojectlibvpx>= 0 < 1.15.0-2.11.15.0-2.1
webmprojectlibvpx>= 0 < 1.15.0-2.11.15.0-2.1

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
osv5.4MEDIUM