CVE-2025-13633

8.8

Google · Chrome

A use after free vulnerability in Google Chrome's Digital Credentials component allows a remote attacker to trigger heap corruption via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome could allow a remote attacker to compromise the renderer process and achieve heap corruption via malicious web content.

Vulnerability

This vulnerability is a use after free condition (CWE-416) within the Digital Credentials component, which can be triggered by an unauthenticated remote attacker through a specially crafted HTML page.

Business impact

The exploitation of this vulnerability allows for heap corruption, which can lead to arbitrary code execution within the context of the renderer process. Given the CVSS score of 8.8, this flaw poses a significant risk to user workstations, potentially facilitating data theft or unauthorized system access. Organizations should treat this as a high-priority update to prevent browser-based attacks.

Remediation

Immediate Action: Update all installations of Google Chrome to version 143.0.7499.41 or later to apply the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual browser crashes or unexpected behavior in the renderer process that may indicate attempted exploitation.

Compensating Controls: Ensure that users operate with the principle of least privilege and utilize modern endpoint protection platforms to detect and block malicious web-based payloads.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability represents a significant security risk due to the potential for heap corruption and subsequent code execution. Security teams must prioritize the deployment of the Google Chrome update to all managed devices immediately. Failure to patch may leave systems vulnerable to browser-based attacks that bypass standard security boundaries.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written
  5. Fix documented version 143.0.7499.41 per CVE record

Sources