CVE-2025-0997 is a high-severity use-after-free vulnerability in Google Chrome (prior to version 133.0.6943.98) that could allow a remote attacker to exploit heap corruption through a specially crafted Chrome Extension. The vulnerability has a CVSS score of 8.1 (High), indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received some community discussion and media coverage, including a $55,000 bug bounty payout.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 133.0.6943.98CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 133.0.6943.98, < 133.0.6943.98CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.