CVE-2025-11205
8.8Google · Chrome
A heap buffer overflow in the WebGPU component of Google Chrome allows a remote attacker to trigger heap corruption via a crafted HTML page.
Executive summary
A high-severity heap buffer overflow in Google Chrome WebGPU allows remote attackers to trigger memory corruption, potentially leading to arbitrary code execution.
Vulnerability
This vulnerability is a heap buffer overflow (CWE-122) located in the WebGPU component. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, which then compromises the renderer process.
Business impact
Successful exploitation of this vulnerability allows a remote attacker to corrupt heap memory, which may lead to system compromise or unauthorized code execution within the context of the browser. Given the CVSS score of 8.8, this represents a significant risk to organizational endpoints, potentially facilitating data theft or further lateral movement within the network.
Remediation
Immediate Action: Update Google Chrome to version 141.0.7390.54 or later across all managed devices.
Proactive Monitoring: Review endpoint security logs for unusual browser process behavior or unexpected crashes that may indicate exploitation attempts.
Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web content or memory corruption patterns, while ensuring browser sandbox features remain enabled.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates prompt action to protect browser-based environments. Organizations should prioritize the deployment of the latest Chrome updates to all workstations to mitigate the risk of heap-based memory corruption and potential remote code execution.