Chrome Use-After-Free Flaw Lets Attackers Execute Arbitrary Code
Google has issued a critical security update for the Chrome browser following the identification of a significant use-after-free vulnerability. This flaw, designated as CVE-2025-11756, affects Chrome's Safe Browsing feature and has been rated with high…
Google has issued a critical security update for the Chrome browser following the identification of a significant use-after-free vulnerability. This flaw, designated as CVE-2025-11756, affects Chrome's Safe Browsing feature and has been rated with high severity by Google's security team.
Critical Vulnerability in Chrome's Safe Browsing Feature
A newly discovered security flaw poses a substantial risk to Chrome users globally. Use-after-free vulnerabilities occur when a program continues to use memory after it has been freed, allowing attackers to manipulate that memory space. In this instance, the vulnerability is located within Chrome's Safe Browsing component, which is intended to protect users from malicious websites and downloads.
Security researcher "asnine" identified and reported this vulnerability on September 25, 2025, receiving a $7,000 reward from Google's bug bounty program. The successful exploitation of this vulnerability could permit attackers to execute arbitrary code on a victim's system, potentially installing malware, stealing sensitive information, or gaining unauthorized access to the affected computer.
The vulnerability's presence in the Safe Browsing feature is particularly concerning as this component operates with elevated privileges to safeguard users against online threats.
In response to this critical flaw, Google has released Chrome version 141.0.7390.107/.108 for Windows and Mac systems, and version 141.0.7390.107 for Linux. The update commenced rollout on October 14, 2025, and will be available to all users in the coming days and weeks.
Google has adhered to its standard security disclosure policy, limiting access to detailed bug information until most users have installed the security patch. This strategy helps prevent exploitation by cybercriminals before users can apply the update.
To identify and prevent similar security issues in future stable Chrome releases, Google's security team employed advanced detection tools, including AddressSanitizer, MemorySanitizer, and other fuzzing technologies.
Google has issued a critical security update for the Chrome browser following the identification of a significant use-after-free vulnerability.
CVE ID CVE-2025-11756
Vulnerability Type Use after free in Safe Browsing
Severity Rating High
CVSS Score Not yet assigned
Affected Component Chrome Safe Browsing
Reporter asnine
Report Date September 25, 2025
Bug Bounty $7,000
Fixed Version Chrome 141.0.7390.107/.108
Chrome users are urged to update their browsers promptly to mitigate the risk posed by this vulnerability. While the browser typically updates automatically, users can manually check for updates by navigating to Settings > About Chrome. Delayed updates increase the risk of exploitation by cybercriminals targeting this specific vulnerability.
This incident underscores the importance of maintaining updated software and the critical role of security researchers in identifying potential threats before they can cause widespread harm.
Based on reporting by GBHackers.
