Use-after-free in Google Chromium - CVE-2025-14372
Published: December 10, 2025 / Updated: December 11, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within Password Manager in Google Chrome. A remote attacker can trick the victim into visiting a specially crafted web page, trigger a use-after-free error and gain access to sensitive information.
Affected software
Microsoft Edge
Google Chrome
Prisma Access Browser
Debian Linux
chromium (Debian package)
How to mitigate CVE-2025-14372
Microsoft Edge - update to 143.0.3650.80
Google Chrome - update to 143.0.7499.109
chromium (Debian package) - addressed in versions 143.0.7499.109-1~deb12u1, 143.0.7499.109-1~deb13u1
Prisma Access Browser - update to 143.37.2.193