CVE-2025-11205

8.8

Google · Chrome

A heap buffer overflow in the WebGPU component of Google Chrome allows a remote attacker to trigger heap corruption via a crafted HTML page.

Executive summary

A high-severity heap buffer overflow in Google Chrome WebGPU allows remote attackers to trigger memory corruption, potentially leading to arbitrary code execution.

Vulnerability

This vulnerability is a heap buffer overflow (CWE-122) located in the WebGPU component. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, which then compromises the renderer process.

Business impact

Successful exploitation of this vulnerability allows a remote attacker to corrupt heap memory, which may lead to system compromise or unauthorized code execution within the context of the browser. Given the CVSS score of 8.8, this represents a significant risk to organizational endpoints, potentially facilitating data theft or further lateral movement within the network.

Remediation

Immediate Action: Update Google Chrome to version 141.0.7390.54 or later across all managed devices.

Proactive Monitoring: Review endpoint security logs for unusual browser process behavior or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web content or memory corruption patterns, while ensuring browser sandbox features remain enabled.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates prompt action to protect browser-based environments. Organizations should prioritize the deployment of the latest Chrome updates to all workstations to mitigate the risk of heap-based memory corruption and potential remote code execution.

More Google CVEs

Sources