WebRTC Use After Free Vulnerability in Google Chrome
CVE-2025-7657

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
15 July 2025

What is CVE-2025-7657?

A usage after free vulnerability in WebRTC within Google Chrome versions prior to 138.0.7204.157 could allow an attacker to exploit heap corruption through the delivery of a specially-crafted HTML page. This condition poses a risk as it may lead to unexpected behaviors and potential data exposure. Users are advised to update to the latest version of Google Chrome to mitigate these risks.

Affected Version(s)

Chrome 138.0.7204.157

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7657 : WebRTC Use After Free Vulnerability in Google Chrome