PT-2025-50714 · Google · Google Chrome
Published
2025-12-11
·
Updated
2026-01-17
·
CVE-2025-36934
CVSS v3.1
7.4
High
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google (affected versions not specified)
Description
The issue is a use after free condition stemming from a race condition within the
bigo worker thread function located in private/google-modules/video/gchips/bigo.c. This can result in local privilege escalation without requiring additional execution privileges or user interaction. The vulnerability was discovered in the BigWave driver and can be exploited using specially crafted MP4 files to achieve arbitrary code execution in the mediacodec context, followed by chaining to the vulnerability for kernel privilege escalation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Use After Free
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome