
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14765 is a use-after-free vulnerability in the WebGPU component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported anonymously on 2025-09-30 and publicly disclosed on December 16, 2025, when Google released Chrome 143.0.7499.146/.147 to address it. Affected versions include all Google Chrome releases prior to 143.0.7499.147, as well as Microsoft Edge (Chromium-based) prior to its corresponding patched release. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free) and resides in Chrome's WebGPU implementation. A use-after-free condition occurs when the browser accesses memory that has already been freed, allowing an attacker to corrupt heap memory by serving a specially crafted HTML page. Exploitation requires user interaction — specifically, a victim visiting or being redirected to a malicious webpage — but no authentication or elevated privileges are needed. The Chromium issue tracker references bug ID 448294721 for this vulnerability (Chrome Releases).
Successful exploitation can lead to heap corruption, enabling a remote attacker to achieve arbitrary code execution within the Chrome renderer process. The vulnerability has high impact on confidentiality, integrity, and availability — an attacker could exfiltrate sensitive browser data, modify system state, or cause application crashes. Combined with a sandbox escape, this could result in full system compromise; real-world exploitation has been documented in the wild (Feedly).
cmd.exe, powershell.exe, bash, curl) that are not typical browser behavior; Chrome processes crashing repeatedly with heap corruption errors.Google has released Chrome 143.0.7499.146 (Linux) and 143.0.7499.147 (Windows/Mac) to address this vulnerability; all users should update immediately via Chrome's built-in update mechanism or by downloading from the official site. Microsoft has also released a patched version of Edge Chromium — users should apply the corresponding Edge update. As a temporary workaround if patching is not immediately possible, consider disabling WebGPU via enterprise policy, restricting access to untrusted websites using web filtering, and monitoring for suspicious Chrome extension installations. ChromeOS users should apply the ChromeOS stable channel update released on December 17, 2025 (Chrome Releases, Microsoft MSRC).
Google issued an emergency patch on December 16, 2025, describing the fix as part of a two-vulnerability security update and awarding a $10,000 bug bounty to the anonymous reporter. Security outlets including Malwarebytes, CyberSecurityNews, GBHackers, and SecurityOnline covered the release, emphasizing that both Chrome flaws (CVE-2025-14765 and CVE-2025-14766) could be triggered simply by browsing the web. Malwarebytes specifically highlighted the drive-by nature of the attack in their coverage titled "Two Chrome flaws could be triggered by simply browsing the web — update now." Community sentiment on platforms like Bluesky and Infosec.exchange reflected urgency around patching, with multiple security researchers amplifying the advisory (Chrome Releases, Malwarebytes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."