Chrome Password Manager use-after-free security flaw (CVE-2025-14372)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2025-14372 is a use-after-free in Chrome’s Password Manager that Google patched in the December 10 Chrome security update. The flaw affects a core password-handling component and was reported on November 14, 2025 by Weipeng Jiang (@Krace) of VRI. Google rates the issue medium severity, and the fix is part of a broader release that closed multiple Chrome zero-days.
Related Happenings
Chromium JavaScript background RCE flaw
Vulnerability
H score16
First: 21.05.2026 21:13
Last: 21.05.2026 21:13
Sources 1
About this happening:
The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Chromium JavaScript background RCE flaw
VulnerabilityAbout this happening: The unfixed Chromium flaw keeps JavaScript running after the browser is closed, creating remote code execution risk across Chromium-based browsers. A malicious sit...
Google Chrome 146 adds Device Bound Session Credentials to block session-cookie theft
Security Tool/Service
H score11
First: 09.04.2026 21:33
Last: 09.04.2026 21:33
Sources 1
About this happening:
Google has rolled out Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, binding sessions to device hardware to blunt infostealer malware that steals s...
Google Chrome 146 adds Device Bound Session Credentials to block session-cookie theft
Security Tool/ServiceAbout this happening: Google has rolled out Device Bound Session Credentials (DBSC) in Chrome 146 for Windows, binding sessions to device hardware to blunt infostealer malware that steals s...
QuickLens - Search Screen with Google Lens hit by network compromise
Incident
H score57
First: 28.02.2026 21:18
Last: 28.02.2026 21:18
Sources 1
About this happening:
The QuickLens - Search Screen with Google Lens Chrome extension was compromised and used to push malware to about 7,000 users, creating risk of credential theft*...
QuickLens - Search Screen with Google Lens hit by network compromise
IncidentAbout this happening: The QuickLens - Search Screen with Google Lens Chrome extension was compromised and used to push malware to about 7,000 users, creating risk of credential theft*...
Chrome undisclosed high-severity 466192044 active exploitation security flaw
Vulnerability
H score5
First: 11.12.2025 09:09
Last: 11.12.2025 09:09
Sources 1
About this happening:
Chrome has an undisclosed high-severity flaw tracked as Chromium issue tracker ID 466192044 that is actively exploited in the wild, putting browser users at immedi...
Chrome undisclosed high-severity 466192044 active exploitation security flaw
VulnerabilityAbout this happening: Chrome has an undisclosed high-severity flaw tracked as Chromium issue tracker ID 466192044 that is actively exploited in the wild, putting browser users at immedi...
Chromium Blink document.title crash security flaw
Vulnerability
H score0
First: 30.10.2025 16:45
Last: 30.10.2025 16:45
Sources 1
About this happening:
Brash is a Chromium Blink vulnerability that can crash Google Chrome and other Chromium-based browsers in 15-60 seconds by abusing unthrottled `document.title`...
Chromium Blink document.title crash security flaw
VulnerabilityAbout this happening: Brash is a Chromium Blink vulnerability that can crash Google Chrome and other Chromium-based browsers in 15-60 seconds by abusing unthrottled `document.title`...
Timeline
-
11.12.2025 12:15 2 articles · 7mo ago
Chrome security update patches CVE-2025-14372
Mitigation Patch UpdateGoogle issued a Chrome security update on December 10, 2025 that patched CVE-2025-14372, which Google described as a use-after-free in Chrome’s Password Manager and rated at medium severity.
Show sources
- Google Releases Critical Chrome Security Update to Address Three Zero-Days — www.infosecurity-magazine.com — 11.12.2025 12:15
- Google Releases Critical Chrome Security Update to Address Three Zero-Days — www.infosecurity-magazine.com — 11.12.2025 12:15
-
14.11.2025 02:00 1 articles · 8mo ago
Chrome Password Manager flaw reported to Google
Initial DisclosureWeipeng Jiang (@Krace) of the Vulnerability Research Institute (VRI) reported a use-after-free in Chrome’s Password Manager to Google on November 14, 2025, establishing CVE-2025-14372 as a disclosed browser security issue affecting password handling.
Show sources
- Google Releases Critical Chrome Security Update to Address Three Zero-Days — www.infosecurity-magazine.com — 11.12.2025 12:15