CVE-2025-11756

8.8

Google · Chrome

A use after free vulnerability in Google Chrome's Safe Browsing component allows a remote attacker to perform out of bounds memory access via a crafted HTML page.

Executive summary

A high severity use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code or cause memory corruption through malicious web content.

Vulnerability

This is a use after free vulnerability located in the Safe Browsing component. An unauthenticated remote attacker can exploit this flaw by enticing a user to visit a crafted HTML page, leading to out of bounds memory access.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for significant impact on system integrity and confidentiality. Successful exploitation allows a remote attacker to compromise the renderer process, which may lead to arbitrary code execution, unauthorized data access, or application instability, potentially impacting organizational productivity and data security.

Remediation

Immediate Action: Update Google Chrome to version 141.0.7390.107 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Review endpoint security logs for unexpected browser crashes or suspicious memory access patterns associated with the Chrome renderer process.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web content or exploit attempts targeting browser memory corruption vulnerabilities.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity of this memory corruption vulnerability and its potential for remote code execution, organizations must prioritize the deployment of the latest Chrome security updates. Ensure that all managed systems are running the patched version to prevent potential exploitation via malicious web navigation.

More Google CVEs

Sources