CVE-2025-5283: Use after free in libvpx
A double-free could have occurred in vpxcodecencinitmulti after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.
Other sources
A double-free could have occurred in vpxcodecencinitmulti after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash.
— Mozilla
Chromium: CVE-2025-5283 Use after free in libvpx
— Microsoft
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
— NVD
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5283?
The severity of CVE-2025-5283 is classified as Medium.
How do I fix CVE-2025-5283?
To fix CVE-2025-5283, update Google Chrome to version 137.0.7151.55 or later.
What type of vulnerability is CVE-2025-5283?
CVE-2025-5283 is a Use after free vulnerability in libvpx in Google Chrome.
Can CVE-2025-5283 be exploited remotely?
Yes, CVE-2025-5283 can be exploited by a remote attacker via a crafted HTML page.
Which versions of Google Chrome are affected by CVE-2025-5283?
Google Chrome versions prior to 137.0.7151.55 are affected by CVE-2025-5283.