Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Multiple Google Chrome Flaws Allow Attackers to Execute Arbitrary Code

Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, and version 141.0.7390.65 for Linux. This update addresses three significant security vulnerabilities related to memory handling errors that could potentially allow attackers to…

Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, and version 141.0.7390.65 for Linux. This update addresses three significant security vulnerabilities related to memory handling errors that could potentially allow attackers to execute arbitrary code within the browser.

These vulnerabilities were identified by external researchers through Google's vulnerability disclosure program. The rewards for these discoveries ranged from $3,000 to $5,000, depending on the complexity and severity of the issue.

CVE-2025-11458: A high-severity heap buffer overflow in Chrome Sync, discovered by "raven" at KunLun Lab, which can be exploited by crafting malicious synchronization data. This vulnerability was reported on September 5, 2025, and earned a $5,000 reward. CVE-2025-11460: A high-severity use-after-free flaw in the Storage component, disclosed by researcher Sombra on September 23, 2025. This flaw allows memory corruption via specially designed scripts or web pages. CVE-2025-11211: A medium-severity out-of-bounds read in WebCodecs, reported by Jakob Košir on August 29, 2025. It involves supplying malformed input to the media decoding API, potentially leading to data corruption. A $3,000 reward was issued for this discovery.

Users should update to Chrome 141.0.7390.65/.66 immediately. Automatic updates are enabled by default, but users can manually verify the update by navigating to the “About Google Chrome” section in their browser settings.

Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, and version 141.0.7390.65 for Linux.
John Mason · Thehackingpost

Enterprises managing Chrome through group policies or management consoles should ensure the update is deployed across all endpoints promptly.

Web developers and administrators are advised to maintain strict Content Security Policy (CSP) headers and sanitize user-supplied data to limit the execution of untrusted scripts.

Security teams may consider deploying tools like AddressSanitizer and Control Flow Integrity to detect similar issues in early development stages. Google acknowledges its security partners, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL, for their assistance in detection and prevention efforts.

Advertisement

Collaboration between researchers and vendors is essential to maintain the security of browsers and web applications.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories