Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser

Posted on October 2, 2025October 2, 2025 By CWS

Google has launched Chrome 141 to handle 21 safety vulnerabilities, together with crucial flaws that might enable attackers to crash browsers and doubtlessly execute malicious code.

The replace, rolling out throughout Home windows, Mac, and Linux platforms, patches a number of high-severity vulnerabilities that pose vital dangers to person safety.

Probably the most extreme vulnerability addressed is CVE-2025-11205, a heap buffer overflow in WebGPU that earned safety researcher Atte Kettunen from OUSPG a $25,000 bounty.

This high-severity flaw might doubtlessly enable attackers to execute arbitrary code or crash the browser by exploiting reminiscence corruption within the WebGPU implementation.

One other vital heap buffer overflow vulnerability, CVE-2025-11206, impacts Chrome’s video processing performance. Found by researcher Elias Hohl, this high-severity flaw earned a $4,000 reward and will allow attackers to control video rendering processes to trigger browser instability or crashes.

Info Leakage and Implementation Vulnerabilities

Chrome 141 addresses a number of medium-severity vulnerabilities that might compromise person privateness and browser performance.

CVE-2025-11207 represents a side-channel data leakage vulnerability in Chrome’s storage system, doubtlessly permitting attackers to extract delicate information by means of timing assaults or different side-channel strategies.

A number of inappropriate implementation vulnerabilities have an effect on core browser elements, together with the Media system (CVE-2025-11208, CVE-2025-11212) and Omnibox performance (CVE-2025-11209, CVE-2025-11213). These flaws might allow attackers to control browser conduct or entry unintended performance.

The replace contains crucial fixes for Chrome’s V8 JavaScript engine, addressing CVE-2025-11215 (off-by-one error) and CVE-2025-11219 (use-after-free vulnerability).

Each vulnerabilities have been found by Google’s Large Sleep AI system, highlighting the corporate’s funding in automated vulnerability detection. These JavaScript engine flaws might enable attackers to execute malicious code by means of crafted internet content material.

Google distributed over $50,000 in bug bounty rewards to exterior safety researchers who found these vulnerabilities.

The best particular person payout of $25,000 displays the severity of the WebGPU heap buffer overflow, whereas different rewards ranged from $1,000 to $5,000 relying on vulnerability affect and exploitability.

The Chrome safety crew emphasised that entry to detailed vulnerability data stays restricted till most customers replace their browsers. This method prevents malicious actors from exploiting recognized vulnerabilities earlier than patches are extensively deployed.

Chrome 141.0.7390.54 for Linux and variations 141.0.7390.54/55 for Home windows and Mac at the moment are accessible by means of automated updates.

Customers ought to guarantee their browsers replace routinely or manually examine for updates by means of Chrome’s settings menu to guard in opposition to these critical safety vulnerabilities that might end in browser crashes or compromise system safety.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Attackers, Browser, Chrome, Crash, Patch, Security, Update, Vulnerabilities

Post navigation

Previous Post: 1.5 Million Impacted by Allianz Life Data Breach
Next Post: Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories

Related Posts

GitHub Copilot RCE Vulnerability via Prompt Injection Leads to Full System Compromise Cyber Security News
Chinese Salt Typhoon and UNC4841 Hackers Teamed Up to Attack Government and Corporate Infrastructure Cyber Security News
Aembit Extends Secretless CI/CD with Credential Lifecycle Management for GitLab Cyber Security News
Hackers Use Legitimate Drivers to Kill Antivirus Processes and Lower The System’s Defenses Cyber Security News
Microsoft Confirms Laying Off 9,000 Employees, Impacting 4% of its Workforce Cyber Security News
New Malware in npm Package Steals Browser Passwords Using Steganographic QR Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence
  • Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
  • MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
  • Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence
  • Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
  • MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
  • Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark