Skip to content
Fedora 43: Chromium High CVE-2025-14765/14766 Heap Corruption Advisory

Fedora 43: Chromium High CVE-2025-14765/14766 Heap Corruption Advisory

Linuxsecurity LinuxSecurity Advisories December 20, 2025

Chromium is an open-source web browser, powered by WebKit (Blink). Update Information : Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

Chromium is an open-source web browser, powered by WebKit (Blink).

Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 * Force dark mode when auto dark mode web content is on

* Wed Dec 17 2025 Than Ngo - 143.0.7499.146-1 - Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 - Force dark mode when auto dark mode web content is on - Remove omnibox- -Improve-cutout-mouse-handling-for-Wayla patch, as it's merged

* Wed Dec 17 2025 Than Ngo - 143.0.7499.146-1 - Update to 143.0.7499.146 * High CVE-2025-14765: Use after free in WebGPU * High CVE-2025-14766: Out of bounds read and write in V8 - Force dark mode when auto dark mode web content is on - Remove omnibox- -Improve-cutout-mouse-handling-for-Wayla patch, as it's merged

[ 1 ] Bug #2423106 - CVE-2025-14765 chromium: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption [fedora-all] [ 2 ] Bug #2423107 - CVE-2025-14765 chromium: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption [epel-all] [ 3 ] Bug #2423110 - CVE-2025-14766 chromium: Google Chrome V8: Out-of-bounds read and write leads to heap corruption [epel-all] [ 4 ] Bug #2423111 - CVE-2025-14766 chromium: Google Chrome V8: Out-of-bounds read and write leads to heap corruption [fedora-all]

[ 1 ] Bug #2423106 - CVE-2025-14765 chromium: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption [fedora-all] [ 2 ] Bug #2423107 - CVE-2025-14765 chromium: Chromium: Use after free in WebGPU allows remote attacker to exploit heap corruption [epel-all] [ 3 ] Bug #2423110 - CVE-2025-14766 chromium: Google Chrome V8: Out-of-bounds read and write leads to heap corruption [epel-all] [ 4 ] Bug #2423111 - CVE-2025-14766 chromium: Google Chrome V8: Out-of-bounds read and write leads to heap corruption [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-cd7567466d' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities