CVE-2025-14765
vulnerability analysis and mitigation

Overview

CVE-2025-14765 is a use-after-free vulnerability in the WebGPU component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported anonymously on 2025-09-30 and publicly disclosed on December 16, 2025, when Google released Chrome 143.0.7499.146/.147 to address it. Affected versions include all Google Chrome releases prior to 143.0.7499.147, as well as Microsoft Edge (Chromium-based) prior to its corresponding patched release. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and resides in Chrome's WebGPU implementation. A use-after-free condition occurs when the browser accesses memory that has already been freed, allowing an attacker to corrupt heap memory by serving a specially crafted HTML page. Exploitation requires user interaction — specifically, a victim visiting or being redirected to a malicious webpage — but no authentication or elevated privileges are needed. The Chromium issue tracker references bug ID 448294721 for this vulnerability (Chrome Releases).

Impact

Successful exploitation can lead to heap corruption, enabling a remote attacker to achieve arbitrary code execution within the Chrome renderer process. The vulnerability has high impact on confidentiality, integrity, and availability — an attacker could exfiltrate sensitive browser data, modify system state, or cause application crashes. Combined with a sandbox escape, this could result in full system compromise; real-world exploitation has been documented in the wild (Feedly).

Exploitation steps

  1. Reconnaissance: Identify targets running unpatched Google Chrome (prior to 143.0.7499.147) or Microsoft Edge (Chromium-based) using passive fingerprinting or social engineering.
  2. Craft malicious HTML page: Develop a webpage that triggers the WebGPU use-after-free condition by manipulating GPU resource objects in a way that causes the browser to access freed memory (e.g., creating and destroying WebGPU buffers/textures in a specific sequence).
  3. Deliver payload: Host the malicious page on an attacker-controlled server and lure the victim via phishing emails, malicious ads, or compromised websites — user interaction (visiting the page) is required.
  4. Trigger heap corruption: When the victim's browser renders the page, the WebGPU component accesses freed memory, causing heap corruption that can be leveraged to redirect code execution.
  5. Achieve code execution: Exploit the heap corruption to execute arbitrary shellcode within the Chrome renderer process, potentially enabling data theft, credential harvesting, or further exploitation with a sandbox escape (Chrome Releases).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser process to unknown external IPs following visits to unfamiliar or suspicious websites; traffic to domains hosting malicious WebGPU content.
  • Process: Unusual child processes spawned by Chrome's renderer process (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser behavior; Chrome processes crashing repeatedly with heap corruption errors.
  • Logs: Browser crash reports referencing WebGPU or GPU process memory errors; system event logs showing abnormal Chrome process terminations or restarts.
  • File System: Unexpected files written to user profile directories or temp folders by the Chrome process; new or modified browser extensions with credential-access permissions installed without user consent (Feedly).

Mitigation and workarounds

Google has released Chrome 143.0.7499.146 (Linux) and 143.0.7499.147 (Windows/Mac) to address this vulnerability; all users should update immediately via Chrome's built-in update mechanism or by downloading from the official site. Microsoft has also released a patched version of Edge Chromium — users should apply the corresponding Edge update. As a temporary workaround if patching is not immediately possible, consider disabling WebGPU via enterprise policy, restricting access to untrusted websites using web filtering, and monitoring for suspicious Chrome extension installations. ChromeOS users should apply the ChromeOS stable channel update released on December 17, 2025 (Chrome Releases, Microsoft MSRC).

Community reactions

Google issued an emergency patch on December 16, 2025, describing the fix as part of a two-vulnerability security update and awarding a $10,000 bug bounty to the anonymous reporter. Security outlets including Malwarebytes, CyberSecurityNews, GBHackers, and SecurityOnline covered the release, emphasizing that both Chrome flaws (CVE-2025-14765 and CVE-2025-14766) could be triggered simply by browsing the web. Malwarebytes specifically highlighted the drive-by nature of the attack in their coverage titled "Two Chrome flaws could be triggered by simply browsing the web — update now." Community sentiment on platforms like Bluesky and Infosec.exchange reflected urgency around patching, with multiple security researchers amplifying the advisory (Chrome Releases, Malwarebytes).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management