PT-2025-31358 · Google +1 · Google Chrome +1

Published

2025-07-29

·

Updated

2025-08-01

·

CVE-2025-8292

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Chromium versions prior to 138.0.7204.183

Google Chrome versions prior to 138.0.7204.183

**Description:**

A use-after-free vulnerability exists in the Media Stream component of Chromium and Google Chrome. This allows a remote attacker to potentially exploit heap corruption via a crafted HTML page, potentially leading to arbitrary code execution. The vulnerability involves accessing pointers to SpeechRecognitionMediaStreamAudioSinks after they have been destroyed.

**Recommendations:**

Chromium versions prior to 138.0.7204.183 should be upgraded to version 138.0.7204.183 or later.

Google Chrome versions prior to 138.0.7204.183 should be upgraded to version 138.0.7204.183 or later.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2025-8292
DSA-5968-1

Affected Products

Debian
Google Chrome