Live
Critical Bluetooth Flaw CVE-2025-27490 Patched: Full System Compromise Possible via Airborne Attack·MSFT +2.1%Microsoft's Hidden PowerPoint Flaw: Why CVE-2025-54908 Evades Verification but Demands Action·NVDA +0.2%Microsoft Patches Excel Code Execution Flaw CVE-2025-54904, but Mac LTSC Still Exposed·GOOGL +1.7%Urgent Excel Security Fix: Use-After-Free Bug Opens Door to Code Execution — Mac LTSC Patches Delayed·AMZN +1.1%Microsoft Warns of Actively Targeted Excel Use-After-Free Flaw CVE-2025-54896·MSFT +2.1%Microsoft Patches Use-After-Free in Windows XAML DatePickerFlyout That Could Elevate Local Privileges·NVDA +0.2%Windows CDPSvc Elevation Flaw (CVE-2025-54102) Patched; Attackers Could Seize SYSTEM Control·GOOGL +1.7%Windows SMBv3 Vulnerability CVE-2025-54101 Could Let Attackers Remotely Execute Code·AMZN +1.1%Critical Bluetooth Flaw CVE-2025-27490 Patched: Full System Compromise Possible via Airborne Attack·MSFT +2.1%Microsoft's Hidden PowerPoint Flaw: Why CVE-2025-54908 Evades Verification but Demands Action·NVDA +0.2%Microsoft Patches Excel Code Execution Flaw CVE-2025-54904, but Mac LTSC Still Exposed·GOOGL +1.7%Urgent Excel Security Fix: Use-After-Free Bug Opens Door to Code Execution — Mac LTSC Patches Delayed·AMZN +1.1%Microsoft Warns of Actively Targeted Excel Use-After-Free Flaw CVE-2025-54896·MSFT +2.1%Microsoft Patches Use-After-Free in Windows XAML DatePickerFlyout That Could Elevate Local Privileges·NVDA +0.2%Windows CDPSvc Elevation Flaw (CVE-2025-54102) Patched; Attackers Could Seize SYSTEM Control·GOOGL +1.7%Windows SMBv3 Vulnerability CVE-2025-54101 Could Let Attackers Remotely Execute Code·AMZN +1.1%

Use After Free

The latest Use After Free coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 10:22 PM
Latest Most Read Breaking
Sort
Bluetooth · Bluetooth-privilege-escalation

Critical Bluetooth Flaw CVE-2025-27490 Patched: Full System Compromise Possible via Airborne Attack

Microsoft’s April 2025 Patch Tuesday included a fix for a critical Bluetooth elevation-of-privilege vulnerability, CVE-2025-27490, that allows an attacker within Bluetooth range to escalate...

Advertisement
Asr · Cve-2025-54896

Microsoft Warns of Actively Targeted Excel Use-After-Free Flaw CVE-2025-54896

Microsoft has issued a critical security advisory for CVE-2025-54896, a use-after-free vulnerability in Microsoft Office Excel that could allow attackers to execute arbitrary code on Windows...

SE Security Desk·45w ago
Cve-2025-54111 · Datepickerflyout

Microsoft Patches Use-After-Free in Windows XAML DatePickerFlyout That Could Elevate Local Privileges

Microsoft has assigned CVE-2025-54111 to a use‑after‑free vulnerability in the Windows UI XAML Phone DatePickerFlyout control, warning that an authenticated local attacker could exploit the flaw...

SE Security Desk·45w ago
Cdpsvc · Cve-2025-54102

Windows CDPSvc Elevation Flaw (CVE-2025-54102) Patched; Attackers Could Seize SYSTEM Control

A high-severity vulnerability in the Windows Connected Devices Platform Service (CDPSvc), cataloged as CVE-2025-54102, can be exploited by a low-privileged local attacker to gain NT AUTHORITY\SYSTEM...

SE Security Desk·45w ago
Cve-2025-54101 · Cybersecurity

Windows SMBv3 Vulnerability CVE-2025-54101 Could Let Attackers Remotely Execute Code

A newly disclosed vulnerability in the Windows SMBv3 client could allow attackers to take full control of unpatched systems with nothing more than a network connection. Microsoft’s advisory,...

SE Security Desk·45w ago
Browser Security · Chrome

Google Rushes Chrome 140 Fix for CVE-2025-9864 V8 Memory Bug, Microsoft Edge Also Patched

Google has released a critical security update for its Chrome browser, patching a high-severity use-after-free vulnerability in the V8 JavaScript engine that could let attackers hijack systems...

SE Security Desk·45w ago
Aura Ui · Browser Security

Google Chrome 139.0.7258.127 Plugs Aura Use-After-Free (CVE-2025-8882) and Other High-Severity Bugs

Google has deployed a critical stable-channel update for Chrome, version 139.0.7258.127, closing a use-after-free vulnerability in the Aura UI component tracked as CVE-2025-8882. The patch also...

SE Security Desk·48w ago
Bod 22-01 · Cisa

CISA Orders Patching of 2007 Excel Bug, 2013 IE Flaw, and 2025 WinRAR Zero-Day

On August 12, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog—two of them first disclosed during the...

SE Security Desk·49w ago
Attack Surface Reduction · Cve-2025-53784

Critical Word Flaw CVE-2025-53784 Lets Attackers Hijack PCs via Malicious Docs — Patch Immediately

Microsoft’s latest security advisory warns of a memory-corruption flaw in Word—CVE-2025-53784—that hands attackers a local-code-execution foothold from nothing more than a booby-trapped...

SE Security Desk·49w ago