Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac , along with version 141.0.7390.65 for Linux , to address several critical vulnerabilities that could allow attackers to execute code affected systems on .

The update, announced on October 7, 2025, includes three important security fixes that pose serious risks to users worldwide.
See also: Unitree: Recent exploit does not cause a robotic infection
Heap Buffer Overflow and Memory Corruption Errors
The most serious vulnerability in this release is CVE-2025-11458, a heap buffer overflow in Chrome's Sync component. It was discovered by security researcher Raven at KunLun lab on September 5, 2025. The researcher earned a $5,000 reward from Google's Vulnerability Bounty Program. Such bugs occur when a program writes data beyond the bounds of its allocated memory buffer, potentially allowing attackers to affect adjacent memory areas and execute arbitrary code.
The second critical vulnerability, CVE-2025-11460, is a Use-After-Free flaw in Chrome's Storage component. It was reported by researcher Sombra on September 23, 2025. This high-severity flaw occurs when the browser attempts to access memory that has already been freed, creating opportunities for attackers to manipulate memory allocation and achieve code execution. Use-after-free vulnerabilities are particularly dangerous as they can lead to a complete system compromise when successfully exploited.

The third vulnerability, CVE-2025-11211, addresses an “out-of-bounds read” in WebCodecs, reported by Jakob Košir on August 29, 2025. This medium severity bug allows attackers to read memory, potentially exposing sensitive information or facilitating further exploit chains.
See also: Vulnerability in Kibana Crowdstrike Connector exposes protected credentials
Chrome Vulnerabilities: Protection
Google's security team used multiple advanced detection methodologies to identify these vulnerabilities, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL fuzzing techniques. These automated security testing continuously analyze Chrome code for memory corruption, race conditions, and other critical security bugs before they reach production environments.
The Chrome development team has implemented comprehensive mitigation strategies into the browser architecture, including sandboxing mechanisms that isolate rendering processes and limit the potential impact of successful exploits.
See also: 13-year-old RCE vulnerability in Redis allows full host access

However, users should install the security update immediately, as Google is restricting access to detailed vulnerability information until the majority of users have updated their browsers (to prevent widespread exploitation of these critical bugs).
