CVE-2025-0437: High Out of bounds read in Metrics
Chromium: CVE-2025-0437 Out of bounds read in Metrics
Other sources
Out of bounds read in Metrics in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0437?
CVE-2025-0437 has been classified with a medium severity level indicating potential risks that require attention.
How do I fix CVE-2025-0437?
To remediate CVE-2025-0437, ensure that your Google Chrome is updated to version 132.0.6834.83 or later, and that Microsoft Edge (Chromium-based) is updated as recommended by Microsoft.
Which versions of Google Chrome are affected by CVE-2025-0437?
Google Chrome versions prior to 132.0.6834.83 are affected by CVE-2025-0437.
Which versions of Microsoft Edge are affected by CVE-2025-0437?
Microsoft Edge versions prior to 132.0.2957.115 are affected by CVE-2025-0437.
What kind of vulnerability is CVE-2025-0437?
CVE-2025-0437 is identified as an out of bounds read vulnerability that can potentially allow unauthorized access to adjacent memory.