CVE-2025-1916: Use after free in Profiles.
Chromium: CVE-2025-1916 Use after free in Profiles
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Profiles in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1916?
The severity of CVE-2025-1916 is classified as Medium.
How do I fix CVE-2025-1916?
To fix CVE-2025-1916, update Google Chrome to version 134.0.6998.35 or later.
What is CVE-2025-1916?
CVE-2025-1916 is a use after free vulnerability in Google Chrome that could lead to heap corruption when exploited.
Who is affected by CVE-2025-1916?
Users of Google Chrome prior to version 134.0.6998.35 are affected by CVE-2025-1916.
How can attackers exploit CVE-2025-1916?
Attackers can exploit CVE-2025-1916 by convincing users to install a malicious extension that uses crafted HTML.