Heap Corruption Vulnerability in Media Component of Google Chrome
CVE-2025-5958
8.8HIGH
Key Information:
Badges
👾 Exploit Exists📰 News Worthy
What is CVE-2025-5958?
A use after free vulnerability in the Media component of Google Chrome prior to version 137.0.7151.103 could allow a remote attacker to exploit heap corruption. By crafting a malicious HTML page, an attacker may disrupt memory management practices, posing significant risks to user security and privacy.
Affected Version(s)
Chrome 137.0.7151.103
News Articles
Multiple Chrome Flaws Enable Remote Code Execution by Attackers
The rollout will take place gradually over the coming days and weeks, ensuring smooth deployment and minimal disruption for users.

Multiple Chrome Vulnerabilities Enable Remote Code Execution by Attackers
Google has released an security update for its Chrome browser to address two critical vulnerabilities that could potentially allow attackers to execute malicious code.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
- 📰
First article discovered by Cyber Press
Vulnerability published
Vulnerability Reserved