PT-2025-3887 · Google+5 · Skia+6

Revskills

·

Published

2025-01-19

·

Updated

2025-04-08

·

CVE-2025-0444

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 133.0.6943.53 Microsoft Edge (affected versions not specified)
Description The issue is related to a use after free in Skia, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. Technical details include concurrent access to SkFontationsScalerContext, which may lead to a race condition and use-after-free. The generateYScalePathForGlyphId() function can be called from a COLRv1 SkDrawable.
Recommendations For Google Chrome versions prior to 133.0.6943.53, update to version 133.0.6943.53 or later to resolve the issue. For Microsoft Edge, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to potentially vulnerable components until a patch is available.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2025-2744
ALT-PU-2025-4366
BDU:2025-01274
CVE-2025-0444
DSA-5859-1
MGASA-2025-0091
OPENSUSE-SU-2025:0058-1
OPENSUSE-SU-2025:14742-1

Affected Products

Alt Linux
Astra Linux
Debian
Google Chrome
Edge
Red Os
Skia