← Intelligence Center

Google Chrome Vulnerability Could Allow for Arbitrary Code Execution (CVE-2025-8292)

PublishedJul 29, 2025
Updated
VendorGoogle
SeverityHigh
Known ExploitedNo
Advisory IDINTEL-000023
CVEs
CVE-2025-8292
Products
  • Chrome prior to 138.0.7204.183/.184 for Windows and Mac
  • Chrome prior to 138.0.7204.183 for Linux

Executive Summary

MS-ISAC Advisory 2025-068 (issued 7/29/2025): a use-after-free vulnerability in Media Stream in Google Chrome could allow for arbitrary code execution in the context of the logged-on user via drive-by compromise. There are no reports of this vulnerability being exploited in the wild at this time.

Municipal Impact

MS-ISAC rates the risk as High for large, medium, and small government entities, so municipal agencies should update Chrome immediately.

SMB Impact

MS-ISAC rates the risk as High for large, medium, and small business entities and Low for home users.

Recommended Actions

  1. Apply appropriate updates provided by Google to vulnerable systems immediately after appropriate testing.
  2. Ensure use of only fully supported browsers and apply browser updates.
  3. Apply the principle of least privilege to all systems and services.

Grey Matter Analysis

Analysis pending review.

References

Tags

GoogleChromeCVE-2025-8292Use After FreeBrowserTA0001T1189

Related Intelligence

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter