PT-2025-31358 · Google +1 · Google Chrome +1
Published
2025-07-29
·
Updated
2025-08-01
·
CVE-2025-8292
8.8
High
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Chromium versions prior to 138.0.7204.183
Google Chrome versions prior to 138.0.7204.183
**Description:**
A use-after-free vulnerability exists in the Media Stream component of Chromium and Google Chrome. This allows a remote attacker to potentially exploit heap corruption via a crafted HTML page, potentially leading to arbitrary code execution. The vulnerability involves accessing pointers to SpeechRecognitionMediaStreamAudioSinks after they have been destroyed.
**Recommendations:**
Chromium versions prior to 138.0.7204.183 should be upgraded to version 138.0.7204.183 or later.
Google Chrome versions prior to 138.0.7204.183 should be upgraded to version 138.0.7204.183 or later.
Fix
RCE
Use After Free
Weakness Enumeration
Related Identifiers
Affected Products
References · 19
- https://security-tracker.debian.org/tracker/CVE-2025-8292 · Vendor Advisory
- https://security-tracker.debian.org/tracker/DSA-5968-1 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8292 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-8292 · Security Note
- https://security-tracker.debian.org/tracker/source-package/chromium · Vendor Advisory
- https://t.me/msrcreports/2094 · Telegram Post
- https://packages.debian.org/src:chromium · Note
- https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_29.html · Note
- https://twitter.com/windowsforum/status/1951025807255609504 · Twitter Post
- https://twitter.com/CVEnew/status/1950395547149566230 · Twitter Post
- https://twitter.com/rewterz/status/1950813079719088315 · Twitter Post
- https://twitter.com/SecQube/status/1951149426061246570 · Twitter Post
- https://issues.chromium.org/issues/426054987 · Note
- https://twitter.com/the_yellow_fall/status/1950345846677262462 · Twitter Post
- https://twitter.com/EduardsGrebezs/status/1950488831829889448 · Twitter Post