
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13638 is a use-after-free vulnerability in the Media Stream component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher "sherkito" on September 29, 2025, and publicly disclosed on December 2, 2025, as part of the Chrome 143 stable channel release. The vulnerability affects all Google Chrome versions prior to 143.0.7499.40 (Linux) / 143.0.7499.41 (Windows/Mac), as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High), though Google's internal Chromium security severity rating is Low (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free) and resides in Chrome's Media Stream subsystem. A use-after-free occurs when a program continues to use a pointer to memory after that memory has been freed, potentially allowing an attacker to control the freed memory region and corrupt heap data. Exploitation requires user interaction — specifically, a victim visiting a maliciously crafted HTML page — but requires no authentication or special privileges from the attacker. The Chromium issue tracker reference is bug #448046109, though full technical details remain restricted pending broad user update (Chrome Releases).
Successful exploitation could allow a remote attacker to corrupt heap memory, potentially leading to arbitrary code execution within the Chrome renderer process. This would impact confidentiality, integrity, and availability of the affected browser session, with the CVSS assessment rating all three as High. While Chrome's sandbox may limit direct system compromise, heap corruption primitives can serve as a stepping stone for sandbox escape chains when combined with additional vulnerabilities (Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2025-13638. The EPSS score is approximately 0.109%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Chrome Releases).
Google has addressed this vulnerability in Chrome 143.0.7499.40 for Linux and 143.0.7499.41 for Windows and Mac. Microsoft has also released a corresponding update for Edge (Chromium-based). Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or enable automatic updates. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).
The Chrome 143 update, which patches 13 security vulnerabilities including CVE-2025-13638, received broad media coverage. Forbes highlighted the update with urgency for Chrome's approximately 3 billion users. Security outlets including GBHackers, CyberPress, and BleepingComputer covered the release, noting the mix of High and Low severity fixes. The December 2025 Patch Tuesday review by Zero Day Initiative and Rapid7 also referenced the Edge/Chromium updates. Community reaction was generally routine, given the Low internal severity rating assigned by Google to this specific CVE (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."