CVE-2025-10501: High Use after free in WebRTC
Chromium: CVE-2025-10501 Use after free in WebRTC
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10501?
CVE-2025-10501 has a high severity rating due to the potential for exploitation through use after free vulnerabilities in WebRTC.
How do I fix CVE-2025-10501?
To fix CVE-2025-10501, update Google Chrome and Microsoft Edge (Chromium-based) to their latest versions, as these releases include patches for the vulnerability.
Which software is affected by CVE-2025-10501?
CVE-2025-10501 affects Google WebRTC, Microsoft Edge (Chromium-based), and the Microsoft Edge legacy browser version up to 140.0.3485.81.
What kind of attack can exploit CVE-2025-10501?
CVE-2025-10501 can potentially be exploited to execute arbitrary code in the context of the user running the affected software.
Is CVE-2025-10501 a remote code execution vulnerability?
Yes, CVE-2025-10501 is classified as a remote code execution vulnerability due to the implications of a use after free condition.