{"id":7361,"date":"2025-10-02T10:03:44","date_gmt":"2025-10-02T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/02\/chrome-security-update-patch-for-21-vulnerabilities-that-allows-attackers-to-crash-browser\/"},"modified":"2025-10-02T10:03:44","modified_gmt":"2025-10-02T10:03:44","slug":"chrome-security-update-patch-for-21-vulnerabilities-that-allows-attackers-to-crash-browser","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/02\/chrome-security-update-patch-for-21-vulnerabilities-that-allows-attackers-to-crash-browser\/","title":{"rendered":"Chrome Security Update \u2013 Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser"},"content":{"rendered":"<p>    Chrome Security Update \u2013 Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has released Chrome 141 to address 21 security vulnerabilities, including critical flaws that could allow attackers to crash browsers and potentially execute malicious code.<\/p>\n<p>The update, rolling out across Windows, Mac, and Linux platforms, patches several high-severity vulnerabilities that pose significant risks to user security.<\/p>\n<p>The most severe vulnerability addressed is CVE-2025-11205, a heap buffer overflow in WebGPU that earned security researcher Atte Kettunen from OUSPG a $25,000 bounty.<\/p>\n<p>This high-severity flaw could potentially allow attackers to execute arbitrary code or crash the browser by exploiting memory corruption in the WebGPU implementation.<\/p>\n<p>Another significant heap <a href=\"https:\/\/cybersecuritynews.com\/what-is-buffer-overflow\/\" target=\"_blank\" rel=\"noreferrer noopener\">buffer overflow vulnerability<\/a>, CVE-2025-11206, affects Chrome\u2019s video processing functionality. Discovered by researcher Elias Hohl, this high-severity flaw earned a $4,000 reward and could enable attackers to manipulate video rendering processes to cause browser instability or crashes.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-information-leakage-and-implementation-vulnerabilities\"><strong>Information Leakage and Implementation Vulnerabilities<\/strong><\/h2>\n<p>Chrome 141 addresses multiple medium-severity vulnerabilities that could compromise user privacy and browser functionality.<\/p>\n<p>CVE-2025-11207 represents a side-channel information leakage vulnerability in Chrome\u2019s storage system, potentially allowing attackers to extract sensitive data through timing attacks or other <a href=\"https:\/\/cybersecuritynews.com\/tag\/gpu-side-channel\/\" target=\"_blank\" rel=\"noreferrer noopener\">side-channe<\/a>l methods.<\/p>\n<p>Several inappropriate implementation vulnerabilities affect core browser components, including the Media system (CVE-2025-11208, CVE-2025-11212) and Omnibox functionality (CVE-2025-11209, CVE-2025-11213). These flaws could enable attackers to manipulate browser behavior or access unintended functionality.<\/p>\n<p>The update includes critical fixes for Chrome\u2019s V8 JavaScript engine, addressing CVE-2025-11215 (off-by-one error) and CVE-2025-11219 (use-after-free vulnerability).<\/p>\n<p>Both vulnerabilities were discovered by Google\u2019s Big Sleep AI system, highlighting the company\u2019s investment in automated <a href=\"https:\/\/cybersecuritynews.com\/vulnerability-management-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability<\/a> detection. These JavaScript engine flaws could allow attackers to execute malicious code through crafted web content.<\/p>\n<p>Google distributed over $50,000 in bug bounty rewards to external security researchers who discovered these vulnerabilities.<\/p>\n<p>The highest individual payout of $25,000 reflects the severity of the WebGPU heap buffer overflow, while other rewards ranged from $1,000 to $5,000 depending on vulnerability impact and exploitability.<\/p>\n<p>The Chrome security team emphasized that access to detailed vulnerability information remains restricted until most users update their browsers. This approach prevents malicious actors from exploiting known vulnerabilities before patches are widely deployed.<\/p>\n<p>Chrome 141.0.7390.54 for Linux and versions 141.0.7390.54\/55 for Windows and Mac are <a href=\"https:\/\/chromereleases.googleblog.com\/2025\/09\/stable-channel-update-for-desktop_30.html?m=1\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">now available<\/a> through automatic updates.<\/p>\n<p>Users should ensure their browsers update automatically or manually check for updates through Chrome\u2019s settings menu to protect against these serious security vulnerabilities that could result in browser crashes or compromise system security.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-security-updates\/\">Chrome Security Update \u2013 Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-security-updates\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chrome Security Update \u2013 Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser Google has released Chrome 141 to address 21 security vulnerabilities, including critical flaws that could allow attackers to crash browsers and potentially execute malicious code. The update, rolling out across Windows, Mac, and Linux platforms, patches several high-severity vulnerabilities that pose [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-7361","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7361"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7361"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7361\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}