CVE-2025-4372

Published May 6, 2025

Last updated 20 days ago

Overview

Description
Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Source
chrome-cve-admin@google.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

chrome-cve-admin@google.com
CWE-416

Social media

Hype score
Not currently trending
  1. ‼️ Fedora 42 users: Patch Chromium NOW (CVE-2025-4372 – WebAudio UAF exploit). High-risk vulnerability! ▶️ Update command: sudo dnf upgrade --advisory FEDORA-2025-63db6c850f👉 https://t.co/rGMKf08a0Q #Fedora #Security https://t.co/UtZYLS1Nhw

    @Cezar_H_Linux

    12 May 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. https://t.co/fVNcE1HiVJ安全团队发布了#CVE-2025-4372 Chrome WebAudio 组件UAF漏洞的完整PoC分析。包含3种验证方式 和详尽技术报告,有助于安全研究人员了解内存破坏漏洞利用机制。查看: https://t.co/ftxJZbgGDL #infosec #cybersecu

    @met3or

    12 May 2025

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️Vulnerabilidad en Microsoft Edge ❗CVE-2025-4372 ➡️Más info: https://t.co/Ab1y8h7mUM https://t.co/kjb6g7YpV8

    @CERTpy

    9 May 2025

    239 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Actively exploited CVE : CVE-2025-4372

    @transilienceai

    8 May 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🔴 Google acaba de lanzar un parche de seguridad para corregir una vulnerabilidad de uso después de la liberación (UAF) en la API WebAudio de Chrome (CVE-2025-4372) 🧉 https://t.co/43lWxlc0ND

    @MarquisioX

    7 May 2025

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️ Chrome WebAudio Vulnerability Allows attackers to execute malicious code  Read more: https://t.co/hnniofXA6l ✅ CVE-2025-4372, a Use-After-Free (UAF) vulnerability in Chrome's WebAudio API. This flaw potentially enables remote attackers to exploit heap corruption thro

    @The_Cyber_News

    7 May 2025

    332 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  7. CVE-2025-4372 Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium s… https://t.co/VhbPrHhXl0

    @CVEnew

    6 May 2025

    549 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes