CVE-2025-14372: Medium Use after free in Password Manager.
Chromium: CVE-2025-14372 Use after free in Password Manager
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-14372?
CVE-2025-14372 has been rated as high severity due to the potential exploitation through use after free vulnerabilities in the Password Manager.
How do I fix CVE-2025-14372?
To fix CVE-2025-14372, update Google Chrome to version 143.0.7499.109 or later, or update Microsoft Edge to the latest version.
Which browsers are affected by CVE-2025-14372?
CVE-2025-14372 affects Google Chrome and Microsoft Edge (Chromium-based) browsers.
Is CVE-2025-14372 a remote code execution vulnerability?
CVE-2025-14372 could potentially lead to remote code execution if exploited by an attacker.
Was CVE-2025-14372 disclosed publicly?
CVE-2025-14372 was disclosed publicly in the context of a Chrome security update.