PT-2024-10393 · Google+5 · Google Chrome+5

Sakana.S

·

Published

2024-12-18

·

Updated

2025-09-06

·

CVE-2025-0762

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 132.0.6834.159 Microsoft Edge versions prior to 132.0.2957.140
Description The issue is related to a use-after-free vulnerability in the DevTools of Google Chrome and Microsoft Edge, which could allow a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. This vulnerability may enable an attacker to execute arbitrary code or cause a denial of service.
Recommendations For Google Chrome versions prior to 132.0.6834.159, update to version 132.0.6834.159 or later to resolve the issue. For Microsoft Edge versions prior to 132.0.2957.140, update to version 132.0.2957.140 or later to resolve the issue. As a temporary workaround, consider disabling the use of DevTools in Google Chrome and Microsoft Edge until a patch is applied. Restrict access to the DevTools module to minimize the risk of exploitation.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2025-2238
ALT-PU-2025-2945
ALT-PU-2025-3969
ALT-PU-2025-4366
ALT-PU-2025-7539
ALT-PU-2025-8547
BDU:2025-00908
CVE-2025-0762
DSA-5855-1
MGASA-2025-0037
OPENSUSE-SU-2025:0036-1
OPENSUSE-SU-2025:14720-1
OPENSUSE-SU-2025:15531-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Edge
Red Os