Use-after-free in Google Chromium - CVE-2025-1006

 

Use-after-free in Google Chromium - CVE-2025-1006

Published: February 18, 2025 / Updated: February 22, 2025


Vulnerability identifier: #VU104056
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-1006
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within Network in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Prisma Access Browser
Debian Linux
Fedora
Chrome OS
chromium
chromium (Debian package)

How to mitigate CVE-2025-1006

Install update from vendor's website.

Google Chromium - update to 133.0.6943.126
Microsoft Edge - update to 133.0.3065.82
Google Chrome - update to 133.0.6943.126
Chrome OS - update to 132.0.6834.214
chromium - addressed in versions 133.0.6943.126-1.el8, 133.0.6943.126-1.el9, 133.0.6943.126-1.el10_1, 133.0.6943.126-1.fc40, 133.0.6943.126-1.fc41, 133.0.6943.126-1.fc42
chromium (Debian package) - update to 133.0.6943.126-1~deb12u1
Prisma Access Browser - update to 134.7.4.44

External References

Related Security Bulletins