CVE-2025-10500: Use after free in Dawn
Chromium: CVE-2025-10500 Use after free in Dawn
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.0.7339.185 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 140.0.7339.185
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10500?
CVE-2025-10500 is classified as a high-severity vulnerability due to the potential for exploitation through a use after free condition.
How do I fix CVE-2025-10500?
To remediate CVE-2025-10500, users should update Google Chrome to version 140.0.7339.185 or later, or use the latest version of Microsoft Edge that addresses this vulnerability.
Which versions of Chrome are affected by CVE-2025-10500?
CVE-2025-10500 affects Google Chrome versions up to but not including 140.0.7339.185.
Is Microsoft Edge affected by CVE-2025-10500?
Yes, Microsoft Edge (Chromium-based) is affected by CVE-2025-10500 and should be updated to the latest version to mitigate the risk.
Where can I find more information about CVE-2025-10500?
More detailed information about CVE-2025-10500 can be found in the release notes from Google Chrome and Microsoft.