CVE-2025-1426: Heap buffer overflow in GPU
Chromium: CVE-2025-1006 Use after free in Network
Other sources
Heap buffer overflow in GPU in Google Chrome on Android prior to 133.0.6943.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1426?
The severity of CVE-2025-1426 is classified as High.
How do I fix CVE-2025-1426?
To fix CVE-2025-1426, upgrade Google Chrome to version 133.0.6943.126 or later.
What are the potential impacts of CVE-2025-1426?
CVE-2025-1426 could allow a remote attacker to exploit heap corruption via a crafted HTML page.
On which platforms is CVE-2025-1426 affecting Google Chrome?
CVE-2025-1426 affects Google Chrome on Android prior to version 133.0.6943.126.
Is CVE-2025-1426 related to any specific component in Chrome?
CVE-2025-1426 is related to a heap buffer overflow in the GPU component of Google Chrome.