CVE-2025-1916: Use after free in Profiles.
Published Oct 31, 2024
·Updated
Chromium: CVE-2025-1916 Use after free in Profiles
Credit
parkminchan, SSD Labs Korea
Affected Software
4 affected componentsFixes available
Microsoft Edge<134.0.3124.51
Microsoft Edge (Chromium-based)
Google Chrome<134.0.6998.35
Google Chrome<134.0.6998.35
134.0.6998.35
Event History
Oct 31, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Mar 5, 2025
CVE Published
via MITRE·03:48 AM
Data Sourced
via MITRE·03:48 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1916?
The severity of CVE-2025-1916 is classified as Medium.
2
How do I fix CVE-2025-1916?
To fix CVE-2025-1916, update Google Chrome to version 134.0.6998.35 or later.
3
What is CVE-2025-1916?
CVE-2025-1916 is a use after free vulnerability in Google Chrome that could lead to heap corruption when exploited.
4
Who is affected by CVE-2025-1916?
Users of Google Chrome prior to version 134.0.6998.35 are affected by CVE-2025-1916.
5
How can attackers exploit CVE-2025-1916?
Attackers can exploit CVE-2025-1916 by convincing users to install a malicious extension that uses crafted HTML.