Chrome Use After Free Vulnerability Let Attackers Execute Arbitrary Code
Google has released a critical security update for its Chrome browser, addressing a high-severity use-after-free vulnerability that may enable attackers to execute arbitrary code on user systems.
Google has released a critical security update for its Chrome browser, addressing a high-severity use-after-free vulnerability that may enable attackers to execute arbitrary code on user systems.
This patch is included in version 141.0.7390.107 for Linux and version 141.0.7390.107/.108 for Windows and macOS, and is currently being deployed to the Stable channel.
The update's release notes provide comprehensive details, with an expected rollout to most users in the coming days or weeks.
The vulnerability, identified as CVE-2025-11756, exists within Chrome's Safe Browsing feature, which is designed to protect users from malicious websites and phishing attempts.
Independent researcher "as nine" discovered the flaw on September 25, 2025, earning a $7,000 reward through Google's Vulnerability Reward Program.
Use-after-free errors occur when software continues to reference memory that has been freed, potentially causing crashes, data corruption, or exploitation.
The update's release notes provide comprehensive details, with an expected rollout to most users in the coming days or weeks.
Attackers could exploit this vulnerability by injecting and executing malicious code, bypassing security sandboxes and compromising the entire browser environment.
Google has classified the issue as high severity due to its potential for remote exploitation without user interaction. Merely visiting a compromised webpage could trigger the attack.
While no widespread exploitation has been reported, Google has initially restricted detailed information about the bug to ensure that most users update before full details are released.
This approach aligns with Chrome's proactive security measures, where full disclosures are delayed until patches are widely distributed.
The patch was developed with the assistance of Google's detection tools, such as AddressSanitizer, MemorySanitizer, and libFuzzer, which aid in identifying memory-related bugs early in the development process.
Google also acknowledged the contributions of external researchers in identifying other potential flaws during the software release cycle.
Users are advised to update Chrome immediately via the browser's settings menu or through automatic rollout to protect against evolving browser-based threats.
Based on reporting by Cyber Security News.
