CVE-2025-5063 is a high-severity use-after-free vulnerability in Google Chrome's Compositing component, affecting versions prior to 137.0.7151.55. A remote attacker could exploit this flaw by enticing a user to visit a specially crafted HTML page, potentially leading to heap corruption and arbitrary code execution. The vulnerability has a CVSS score of 8.8 (High) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 137.0.7151.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 137.0.7151.55, < 137.0.7151.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.