HomeUpdatesGoogle: Chrome 141 fixes 21 vulnerabilities

Google: Chrome 141 fixes 21 vulnerabilities

Google has released Chrome 141 to address 21 security vulnerabilities , including critical weaknesses that could allow attackers to crash browsers and potentially execute malicious code .

Chrome 141 vulnerabilities

The update, available for Windows, Mac, and Linux, fixes several high-severity vulnerabilities that pose significant risks to user security.

Chrome 141: Two very serious vulnerabilities

The most serious vulnerability addressed is CVE-2025-11205, a heap buffer overflow in WebGPU, which earned security researcher Atte Kettunen a $25,000 bounty. The vulnerability could allow attackers to execute arbitrary code or crash the browser by exploiting memory corruption in the WebGPU implementation.

See also: OneLogin bug allows API Keys to be used to steal OIDC secrets

Another significant heap buffer overflow vulnerability , CVE-2025-11206 , affects Chrome's video processing functionality . It was discovered by researcher Elias Hohl and earned him a $4,000 bounty. It could allow attackers to manipulate video rendering processes to cause instability or crashes in the browser.

Google: Chrome 141 fixes 21 vulnerabilities

Medium severity vulnerabilities

Chrome 141 also addresses multiple medium-severity vulnerabilities that could compromise user privacy and browser functionality . CVE-2025-11207 is a side-channel information leakage vulnerability in Chrome's storage system. It could potentially allow attackers to extract sensitive data via timing attacks or other side-channel methods.

Several inappropriate implementation affect core components of the browser, including the Media (CVE-2025-11208, CVE-2025-11212) and the Omnibox (CVE-2025-11209, CVE-2025-11213). These weaknesses could allow attackers to manipulate browser behavior or gain access to unintended functionality.

See also: Splunk Enterprise: Vulnerabilities allow JavaScript code execution

The update also includes critical fixes for Chrome's V8 JavaScript engine, addressing CVE-2025-11215 (off-by-one bug) and CVE-2025-11219 (use-after-free vulnerability). Both vulnerabilities were discovered by Google's Big Sleep AI system, highlighting the company's investment in automated vulnerability detection. These JavaScript engine weaknesses could allow attackers to execute malicious code via specially crafted web content.

Google: Chrome 141 fixes 21 vulnerabilities

Google has distributed over $50,000 in bug bounty rewards to external security researchers who discovered these vulnerabilities. The Chrome security team emphasized that access to detailed vulnerability information remains limited until most users update their browsers. This approach prevents malicious actors from exploiting known vulnerabilities before fixes are widely available.

See also: CISOs urged to rethink vulnerability management

Chrome 141.0.7390.54 for Linux and versions 141.0.7390.54/55 for Windows and Mac are now available via automatic updates.

Users should ensure that their browsers are updated automatically or manually check for updates through Chrome's settings menu to protect themselves from these serious security vulnerabilities that could lead to browser crashes or compromise system security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS