
2/3 Technical overview: • CVE-2025-3388: Use-after-free in V8 exploitable via malicious JavaScript • CVE-2025-3389: Use-after-free in Dawn (WebGPU) triggered through crafted WebGPU calls • CVE-2025-3390: Use-after-free in DevTools requires social engineering These memory corruption flaws can allow attackers to bypass browser sandbox protections and execute arbitrary code on victim machines.
Post summary
The note discloses three new use‑after‑free vulnerabilities in Chrome’s V8 engine, Dawn WebGPU, and DevTools that could enable sandbox escapes and arbitrary code execution.
