CVE-2025-1006 Details
Description
Use after free in Network in Google Chrome prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted web app. (Chromium security severity: Medium)
A use-after-free vulnerability has been identified in the Network component of Google Chrome, prior to version 133.0.6943.126. This vulnerability allows remote attackers to potentially exploit heap corruption through a crafted web application. The issue arises when network communication errors occur, leading to improper management of stream closure callbacks, which can be manipulated to cause memory corruption.
Users should update to Google Chrome version 133.0.6943.126 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chromereleases.googleblog.com/2025/02/stable-channel-update-for-desktop_18.html | [email protected] | Release Notes |
| https://issues.chromium.org/issues/390590778 | [email protected] | Issue TrackingPermissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google chrome | < 133.0.6943.126 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2025 | Initial Analysis | [email protected] |
| Feb 19, 2025 | CVE Modified | CISA-ADP |
| Feb 19, 2025 | New CVE Received | [email protected] |