Google Chrome Aura Use-After-Free Vulnerability Allowing Heap Corruption

Vulnerability

A use-after-free vulnerability has been identified in the Aura component of Google Chrome, affecting versions prior to 139.0.7258.127. This vulnerability allows remote attackers to exploit heap corruption by convincing users to perform specific UI gestures on a crafted HTML page.

Impact

Exploitation of this vulnerability could lead to heap corruption, potentially allowing for arbitrary code execution.

Remediation

Users can update to Google Chrome version 139.0.7258.127 or later to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.