PT-2025-42318 · Google+4 · Google Chrome+4

Published

2025-01-01

·

Updated

2025-11-30

·

CVE-2025-11756

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 141.0.7390.107 Chromium versions prior to 141.0.7390.107
Description A use-after-free issue exists in the Safe Browsing component of Google Chrome and Chromium. This allows a remote attacker who has compromised the renderer process to potentially perform out-of-bounds memory access via a crafted HTML page. The issue is related to a vulnerability in the RendererURLLoaderThrottle when a resource load was redirected. The vulnerability allows attackers to affect the system and potentially execute malicious code. A researcher named 'asnine' reported the issue and received a bounty of $7,000 for its discovery.
Recommendations Update Google Chrome to version 141.0.7390.107 or later. Update Chromium to version 141.0.7390.107 or later.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-14702
BDU:2025-13191
CVE-2025-11756
DSA-6026-1
OPENSUSE-SU-2025:15639-1
OPENSUSE-SU-2025:20027-1

Affected Products

Alt Linux
Google Chrome
Chromium
Debian
Red Os