CVE-2025-14765
Description
A flaw was found in Chromium (Google Chrome). This vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML (HyperText Markup Language) page due to a use after free in WebGPU (Web Graphics Processing Unit).
Statement
This vulnerability is rated Important for Red Hat due to a use-after-free flaw in WebGPU within chromium-browser. A remote attacker could exploit heap corruption by enticing a user to visit a crafted HTML page, potentially leading to arbitrary code execution in the context of the browser.
Mitigation
To mitigate this issue, users should avoid visiting untrusted websites or opening untrusted HTML content. Employing a robust web browser sandbox, if available and configured, can further limit the potential impact of successful exploitation.
Understanding the Weakness (CWE)
Integrity,Availability,Confidentiality
Technical Impact: Modify Memory; DoS: Crash, Exit, or Restart; Execute Unauthorized Code or Commands
This weakness may result in the corruption of memory, and perhaps instructions, possibly leading to a crash. If the corrupted memory can be effectively controlled, it may be possible to execute arbitrary code.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.