
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14372 is a use-after-free vulnerability in the Password Manager component of Google Chrome, classified as Medium severity by Google. It was reported by Weipeng Jiang (@Krace) of VRI on November 14, 2025, and publicly disclosed on December 10, 2025, when Google released Chrome version 143.0.7499.109/.110 to address it. The vulnerability affects all Google Chrome versions prior to 143.0.7499.109, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 6.1 (Medium) (Google Chrome Release, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Password Manager component when memory is accessed after it has been freed, leading to undefined behavior that an attacker can potentially control. A remote attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a victim, triggers the use-after-free condition in the Password Manager subsystem. Exploitation requires user interaction — specifically, a user visiting a malicious webpage — but no special privileges are needed. The flaw was assigned a bug ID of 460599518 in the Chromium issue tracker, though access to the full bug details remains restricted pending widespread user updates (Google Chrome Release).
Successful exploitation of CVE-2025-14372 could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page, which is the primary high-severity consequence despite the Medium CVSS rating. Beyond sandbox escape, attackers could potentially access or manipulate stored passwords within Chrome's Password Manager, execute arbitrary code within the browser's context, and compromise the confidentiality and integrity of the user's browsing environment. The vulnerability's scope is marked as "Changed" in the CVSS vector, reflecting the potential to impact resources beyond the vulnerable component itself (Google Chrome Release, Feedly).
cmd.exe, /bin/bash, powershell.exe); Chrome renderer or GPU processes exhibiting abnormal CPU or memory usage.Login Data SQLite database).Google has released a patch in Chrome version 143.0.7499.109 for Linux and 143.0.7499.109/.110 for Windows/Mac, which users should update to immediately. Microsoft has also issued a corresponding update for Microsoft Edge (Chromium-based) addressing this vulnerability. Users should enable automatic browser updates to ensure timely patching, and enterprise administrators should prioritize deploying the update via group policy or management tools. As a temporary measure, users can exercise caution when browsing unfamiliar websites and consider disabling Chrome's built-in Password Manager in favor of a standalone password manager until the update is applied (Google Chrome Release, Microsoft MSRC).
The December 10, 2025 Chrome update received significant media attention, primarily due to the co-patched CVE-2025-14174 (ANGLE out-of-bounds flaw) which Google confirmed was actively exploited in the wild. Publications including The Hacker News, The Register, Security Affairs, Infosecurity Magazine, and GBHackers covered the update, often framing it as an emergency patch for an actively exploited Chrome zero-day. Some outlets described CVE-2025-14372 alongside CVE-2025-14174 as part of a broader wave of Chrome zero-days in 2025, with Cyber Insider noting it as the "eighth actively exploited Chrome zero-day of 2025." The CIS also issued an advisory noting that multiple vulnerabilities in this Chrome update could allow for arbitrary code execution (The Hacker News, The Register, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."