CVE-2025-11211
published 2025-11-06CVE-2025-11211: Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.36%
28.3th percentile
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 141.0.7390.65-1~deb12u1 | 141.0.7390.65-1~deb12u1 |
| chromium | chromium | >= 0 < 141.0.7390.65-1~deb13u1 | 141.0.7390.65-1~deb13u1 |
| chromium | chromium | >= 0 < 141.0.7390.65-1 | 141.0.7390.65-1 |
| debian | chromium | < chromium 141.0.7390.65-1~deb12u1 (bookworm) | chromium 141.0.7390.65-1~deb12u1 (bookworm) |
| chrome | < 141.0.7390.54 | 141.0.7390.54 | |
| chrome | >= 141.0.7390.54 < 141.0.7390.54 | 141.0.7390.54 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p97f-m8c4-2pvc: Out of bounds read in Media in Google Chrome prior to 141
ghsa_unreviewed·2025-11-07
CVE-2025-11211 [HIGH] CWE-125 GHSA-p97f-m8c4-2pvc: Out of bounds read in Media in Google Chrome prior to 141
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2025-11211: Out of bounds read in Media in Google Chrome prior to 141
osv·2025-11-06·CVSS 7.5
CVE-2025-11211 [HIGH] CVE-2025-11211: Out of bounds read in Media in Google Chrome prior to 141
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Red Hat
chromium-browser: Out of bounds read in Media
vendor_redhat·2025-11-06·CVSS 7.5
CVE-2025-11211 [HIGH] CWE-125 chromium-browser: Out of bounds read in Media
chromium-browser: Out of bounds read in Media
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Microsoft
Chromium: CVE-2025-11211 Out of bounds read in Media
vendor_msrc·2025-10-14·CVSS 7.5
CVE-2025-11211 [HIGH] Chromium: CVE-2025-11211 Out of bounds read in Media
Chromium: CVE-2025-11211 Out of bounds read in Media
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
FAQ:
Chrome
Stable Channel Update for Desktop: CVE-2025-11211
vendor_chrome·2025-09-30·CVSS 7.5
CVE-2025-11211 [MEDIUM] Stable Channel Update for Desktop: CVE-2025-11211
Stable Channel Update for Desktop
CVE-2025-11211: Out of bounds read in Media. Reported by Kosir Jakob on 2025-08-29 [$2000][ 420734141 ] Medium CVE-2025-11212: Inappropriate implementation in Media
Reported by Ameen Basha M K on 2025-05-28 [$1000][ 443408317 ] Medium CVE-2025-11213: Inappropriate implementation in Omnibox
Severity: medium
Debian
CVE-2025-11211: chromium - Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a re...
vendor_debian·2025·CVSS 7.5
CVE-2025-11211 [HIGH] CVE-2025-11211: chromium - Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a re...
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 141.0.7390.65-1~deb12u1)
bullseye: open
forky: resolved (fixed in 141.0.7390.65-1)
sid: resolved (fixed in 141.0.7390.65-1)
trixie: resolved (fixed in 141.0.7390.65-1~deb13u1)
No detection rules found.
No public exploits indexed.
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review | Qualys
blogs_qualys·2025-10-14
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for October 2025
- Adobe Patches for October 2025
- Zero-day Vulnerabilities Patched in October Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in October Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response with TruRisk Eliminate
- Automating Risk Elimination and Accelerating Response: Meet Agent Sara
- EVALUATE Vendor-Suggested Mitigation withPolicy Audit
- Qualys Monthly Webinar Series
As cybersecurity threats evolve, Microsoft’s October 2025 Patch Tuesday delivers one of the most comprehensive security updates of the year. Here’s a quick breakdown of what you need t
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review
blogs_qualys·2025-10-14
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for October 2025
Adobe Patches for October 2025
Zero-day Vulnerabilities Patched in October Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in October Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response with TruRisk Eliminate
Automating Risk Elimination and Accelerating Response: Meet Agent Sara
EVALUATE Vendor-Suggested Mitigation withPolicy Audit
Qualys Monthly Webinar Series
As cybersecurity threats evolve, Microsoft’s October 2025 Patch Tuesday delivers one of the most comprehensive security updates of the year. Here’s a quick breakdown of what you need to know.
## Mi
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
blogs_bleepingcomputer·2025-10-14·CVSS 7.8
[HIGH] Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
## Lawrence Abrams
80 Elevation of Privilege Vulnerabilities
11 Security Feature Bypass Vulnerabilities
31 Remote Code Execution Vulnerabilities
28 Information Disclosure Vulnerabilities
11 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released today by Microsoft. Therefore, the number of flaws does not include those fixed in Azure, Mariner, Microsoft Edge, and other vulnerabilities earlier this month.
Notably, Windows 10 reaches the end of support today , with this being the last Patch Tuesday where Microsoft provides free security updates to the venerable operating system.
To continue receiving security upd
2025-11-06
Published