PT-2025-38316 · Google+3 · Chromium+4

Published

2025-01-01

·

Updated

2025-12-16

·

CVE-2025-10500

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chromium versions prior to 140.0.7339.185 Chromium versions 140.0.7339.185-1deb12u1 through 140.0.7339.185-1deb13u1 Chromium version 141.0.7390.76-alt0.p11.1
Description A use-after-free issue exists in Dawn within Google Chrome and Microsoft Edge. This flaw allows a remote attacker to potentially exploit heap corruption through a specially crafted HTML page. The vulnerability is related to the WebGPU component. Exploitation of this issue may allow an attacker to execute arbitrary code. Google is aware of an exploit for this issue being used in the wild.
Recommendations Upgrade Chromium to version 140.0.7339.185 or later. Upgrade Chromium to version 140.0.7339.185-1deb12u1 for Debian oldstable (bookworm). Upgrade Chromium to version 140.0.7339.185-1deb13u1 for Debian stable (trixie). Upgrade Chromium to version 141.0.7390.76-alt0.p11.1.

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13054
BDU:2025-11453
CVE-2025-10500
DSA-6004-1

Affected Products

Alt Linux
Chromium
Debian
Google Chrome
Red Os