CVE-2025-7657: High Use after free in WebRTC
Chromium: CVE-2025-7657 Use after free in WebRTC
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome/Chromium (WebRTC)to a version that resolves this vulnerability.Fixed in 138.0.7204.157
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7657?
CVE-2025-7657 is classified as a critical vulnerability that allows sandbox escape in Google Chrome.
How do I fix CVE-2025-7657?
To fix CVE-2025-7657, update Google Chrome to version 138.0.7204.157 or later.
Which software is affected by CVE-2025-7657?
CVE-2025-7657 affects Google Chrome and Microsoft Edge (Chromium-based) versions prior to their respective patches.
Is CVE-2025-7657 being actively exploited?
Yes, CVE-2025-7657 has been reported as being actively exploited in the wild.
Who assigned the CVE-2025-7657 vulnerability?
The CVE-2025-7657 vulnerability was assigned by the Chrome security team.