CVE-2025-2476

Published Mar 19, 2025

Last updated 3 months ago

Overview

Description
Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Source
chrome-cve-admin@google.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

chrome-cve-admin@google.com
CWE-416
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score
Not currently trending
  1. A dangerous new Chrome vulnerability (CVE-2025-2476) is already being exploited — but panic won’t protect you. What will? Prevention based on application isolation. 📘 Read now: https://t.co/V5jSoExRzu k https://t.co/7FqIXvhuep

    @BufferZoneSec

    3 Jun 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Actively exploited CVE : CVE-2025-2476

    @transilienceai

    1 Apr 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. A use-after-free flaw (CVE-2025-2476) in Chrome’s Lens component could allow attackers to exploit heap corruption via malicious web pages. Thanks to the experts from @Qualys for their insights! 🔗 Read more: https://t.co/QBdYMVW2r7 ✍ Kirsten Doyle #BrowserSecurity #ISBNews

    @Info_Sec_Buzz

    26 Mar 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Don’t forget to check your Chrome/Chromium version is at least at 𝟭𝟯𝟰.𝟬.𝟲𝟵𝟵𝟴.𝟭𝟭𝟳. A memory-management bug dubbed CVE-2025-2476 has just been fixed and is tagged “Critical.” Use “About Chrome/Chromium” in the three-dots menu to check… https://t.co/Zdmy2ySHf5

    @duckblog

    21 Mar 2025

    125 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-2476 Use after free in Lens in Google Chrome prior to 134.0.6998.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secu… https://t.co/g29rVAtnUI

    @CVEnew

    19 Mar 2025

    417 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. (CVE-2025-2476)[401029609][Critical][CloseUISync]CloseUISync(https://t.co/xOydVgMW3F) deletes LensPermissionBubbleController during OnPermissionDialogAccept(race condition -> UAF) https://t.co/rfQNyIAx4J https://t.co/brlTEazXdn Reported by SungKwon Lee

    @xvonfers

    19 Mar 2025

    1383 Impressions

    2 Retweets

    5 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

Configurations