
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13721 is a race condition vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability was internally discovered by the Chrome team on 2024-07-23 and publicly disclosed on December 2, 2025, as part of the Chrome 143 stable channel release. It affects all Google Chrome versions prior to 143.0.7499.40 (Linux) and 143.0.7499.41 (Windows/Mac), as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 7.5 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition) within Chrome's V8 JavaScript engine. A race condition arises when two or more concurrent operations access shared memory resources in V8 without proper synchronization, potentially allowing an attacker to corrupt heap memory at a critical timing window. Exploitation requires the victim to visit a specially crafted HTML page, which triggers the race condition remotely over the network; no privileges are required on the attacker's side, but user interaction (visiting the malicious page) is necessary. The attack complexity is rated High, reflecting the timing-dependent nature of race condition exploitation (Chrome Releases, Microsoft MSRC).
Successful exploitation could lead to heap memory corruption within the Chrome V8 engine, potentially enabling arbitrary code execution in the context of the browser process or renderer sandbox. This could result in high confidentiality, integrity, and availability impacts — including unauthorized access to sensitive browser data, modification of browser state, or application crashes. The vulnerability's scope is limited to the affected browser instance, but a successful sandbox escape (chained with additional exploits) could extend impact to the underlying operating system (Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation for CVE-2025-13721. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.061%, indicating a low probability of exploitation in the near term. The Chromium security severity is rated Medium, and the bug was reported internally by the Chrome team (Chrome Releases, Microsoft MSRC).
Google has addressed this vulnerability in Chrome 143.0.7499.40 (Linux) and 143.0.7499.41 (Windows/Mac), released on December 2, 2025. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Users and administrators should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or through enterprise update management tools. No configuration-based workaround is available; upgrading to the patched version is the only remediation (Chrome Releases, Microsoft MSRC).
The Chrome 143 release received broad coverage from security news outlets, with multiple publications noting the batch of 13 security fixes including CVE-2025-13721. Coverage from CyberSecurityNews, GBHackers, Forbes, and Bleeping Computer highlighted the update's importance for Chrome's large user base. The Zero Day Initiative's December 2025 security update review and Sophos's Patch Tuesday blog also referenced the Chrome 143 update in the context of December 2025 patching activity (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."