κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser
άμυνα
.

Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser

02/10/2025

Google has released Chrome 141 to address 21 security vulnerabilities, including critical flaws that could allow attackers to crash browsers and potentially execute malicious code.

The update, rolling out across Windows, Mac, and Linux platforms, patches several high-severity vulnerabilities that pose significant risks to user security.

The most severe vulnerability addressed is CVE-2025-11205, a heap buffer overflow in WebGPU that earned security researcher Atte Kettunen from OUSPG a $25,000 bounty.

This high-severity flaw could potentially allow attackers to execute arbitrary code or crash the browser by exploiting memory corruption in the WebGPU implementation.

Another significant heap buffer overflow vulnerability, CVE-2025-11206, affects Chrome’s video processing functionality. Discovered by researcher Elias Hohl, this high-severity flaw earned a $4,000 reward and could enable attackers to manipulate video rendering processes to cause browser instability or crashes.

Information Leakage and Implementation Vulnerabilities

Chrome 141 addresses multiple medium-severity vulnerabilities that could compromise user privacy and browser functionality.

CVE-2025-11207 represents a side-channel information leakage vulnerability in Chrome’s storage system, potentially allowing attackers to extract sensitive data through timing attacks or other side-channel methods.

Several inappropriate implementation vulnerabilities affect core browser components, including the Media system (CVE-2025-11208, CVE-2025-11212) and Omnibox functionality (CVE-2025-11209, CVE-2025-11213). These flaws could enable attackers to manipulate browser behavior or access unintended functionality.

The update includes critical fixes for Chrome’s V8 JavaScript engine, addressing CVE-2025-11215 (off-by-one error) and CVE-2025-11219 (use-after-free vulnerability).

Both vulnerabilities were discovered by Google’s Big Sleep AI system, highlighting the company’s investment in automated vulnerability detection. These JavaScript engine flaws could allow attackers to execute malicious code through crafted web content.

Google distributed over $50,000 in bug bounty rewards to external security researchers who discovered these vulnerabilities.

The highest individual payout of $25,000 reflects the severity of the WebGPU heap buffer overflow, while other rewards ranged from $1,000 to $5,000 depending on vulnerability impact and exploitability.

The Chrome security team emphasized that access to detailed vulnerability information remains restricted until most users update their browsers. This approach prevents malicious actors from exploiting known vulnerabilities before patches are widely deployed.

Chrome 141.0.7390.54 for Linux and versions 141.0.7390.54/55 for Windows and Mac are now available through automatic updates.

Users should ensure their browsers update automatically or manually check for updates through Chrome’s settings menu to protect against these serious security vulnerabilities that could result in browser crashes or compromise system security.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Source: cybersecuritynews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-10

Your RAM has more than one XMP profile, and here's when to use the others

Enabling XMP or EXPO in the motherboard's BIOS is one of the first things all enthusiasts do after building a new PC. It's an easy way to ensure that you're getting the RAM speed you paid for, and often times doesn't compromise stability. They stand for eXtreme Memory Profile and Extended Profiles for Overclocking, and are different flavors of RAM overclocking validation for Intel and AMD, … [Read More...]

Ditching smart home subscriptions for open-source Home Assistant

I quickly grew tired of having countless smart home subscriptions to create the ultimate tech-laden household. And it's not just the usual suspects, like an alarm system, network switches, or some bulbs requiring cloud support plans. Almost everything you can purchase for the "smart home" can come packing some advanced features that require some sort of recurring fee. Like media subscriptions such … [Read More...]

I migrated my cloud photos to my self-hosted Immich, here's how

Like most people, I've been on the Google Photos bandwagon for years now. Photos of trips, birthdays, receipts, and random food snaps have all been backed up to Google Photos. Initially, it was free and convenient as an add-on perk with my Pixel phone. Over time, I ran into the same problems as everyone else. While the perk disappeared, I was locked in, and my growing library pushed me towards … [Read More...]

I replaced Adobe Premiere with DaVinci Resolve, and I'm not missing out on anything

Leaving my Adobe subscriptions behind felt like a gamble at first. Some tools were easy to replace, especially since there are so many great open-source graphics apps out there. But some were harder to replace – finding a decent alternative for After Effects felt like it took forever. And then there was also Premiere Pro. Source: xda-developers.com … [Read More...]

You have to play these Mario games before the Super Mario Galaxy Movie comes out in 2026

Nintendo announced the sequel to The Super Mario Bros. Movie will be hitting theaters on April 3, 2026. The follow-up is titled The Super Mario Galaxy Movie, and was revealed during the Sepember 2025 Nintendo Direct Presentation as part of the celebration of the 40th anniversary of the Super Mario series. To commemorate the occasion, Nintendo is releasing multiple Mario games for the Nintendo … [Read More...]

This week’s best deal is a ‘kids’ Kindle Paperwhite that’s better than the adult version

Our other favorite deals from this week include refurbished Sonos gear and the 8BitDo Ultimate 2 controller.Oct 4, 2025, 5:00 PM UTCSheena Vasani writes about tech news, reviews gadgets, and helps readers save money by highlighting deals and product recommendations for The Verge.Amazon’s Prime Big Deal Days may bring some great Kindle deals, but if you can’t wait, you don’t have to. Right now, the … [Read More...]

Vicinae is basically Raycast for Linux, and it's (almost) everything I wanted

Recently, I've written quite a bit about Raycast, and how it's my absolute favorite app on macOS, and now on Windows as well, thanks to the recent beta launch. But outside of macOS, I'm more of a Linux user these days, and I recently expressed my wish that Raycast would come there, too. Source: xda-developers.com … [Read More...]

Microsoft sneakily drops DLC discounts that come with Xbox Game Pass

After Microsoft decided to jack up the price of its Xbox Game Pass subscriptions to up to $30 a month, it has another unwelcome surprise for members. In a statement provided to multiple outlets like Insider Gaming, a spokesperson for Microsoft confirmed it has removed the discounts for DLC that come with a Game Pass subscription, replacing them by offering points for its Rewards program.While … [Read More...]

The best Amazon Prime Day deals under $50: Early sales on tech from Apple, Anker, Ring, JBL, Roku and others

Prime Day sales are a great opportunity to nab an expensive bit of shiny new tech you’ve been eying — it’s also an excellent time to get a discount on smaller electronics and accessories. For this list, we compared what’s on sale right now with the stuff we recommend in our guides. For less than $50 each, we found deals on some of our favorite tech including batteries, iPhone paraphernalia, mice, … [Read More...]

4 Linux kernel tweaks I made that actually improved performance

If you want something that offers stability, flexibility, and performance, you'll want to consider a Linux distribution. A major part of what makes this operating system (OS) such an easy recommendation is the kernel, the core of what makes everything work. The Linux kernel manages everything from scheduling processes to managing memory allocation and device communication. It's so good that you … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • Your RAM has more than one XMP profile, and here's when to use the others
  • Ditching smart home subscriptions for open-source Home Assistant
  • I migrated my cloud photos to my self-hosted Immich, here's how
  • I replaced Adobe Premiere with DaVinci Resolve, and I'm not missing out on anything
  • You have to play these Mario games before the Super Mario Galaxy Movie comes out in 2026

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023