PT-2025-41495 · Google+4 · Chromium+5

Published

2025-01-01

·

Updated

2026-02-21

·

CVE-2025-11460

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Chromium versions prior to 141.0.7390.65 Microsoft Edge versions prior to 141.0.7390.65
Description A use-after-free issue exists in the Storage component of Google Chrome and Microsoft Edge browsers. Exploitation of this issue could allow a remote attacker to execute arbitrary code or cause a denial of service. The issue is triggered by a crafted video file. A proof-of-concept exploit is publicly available, demonstrating remote code execution in an unsandboxed process through a heap spray and manipulation of Mojo messages. The vulnerability involves an asynchronous destruction of an indexeddb database, leading to a dangling pointer to the database connection object, which can be reused with user-controlled memory corruption.
Recommendations Chromium versions prior to 141.0.7390.65: Upgrade to version 141.0.7390.65 or later. Microsoft Edge versions prior to 141.0.7390.65: Upgrade to version 141.0.7390.65 or later. Chromium versions 141.0.7390.65-1deb12u1 (bookworm) and 141.0.7390.65-1deb13u1 (trixie): No action is required, as these versions are patched. Chromium versions prior to 141.0.7390.76-alt0.p11.1: Upgrade to version 141.0.7390.76-alt0.p11.1 or later.

Exploit

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13054
BDU:2025-13067
CVE-2025-11460
DSA-6021-1
OPENSUSE-SU-2025:15622-1
OPENSUSE-SU-2025:20020-1

Affected Products

Alt Linux
Chromium
Debian
Google Chrome
Edge
Red Os