CVE-2025-11458Heap-based Buffer Overflow in Google Chrome

Severity
8.1HIGHNVD
EPSS
0.0%
top 86.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateNov 7

Description

Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages6 packages

CVEListV5google/chrome141.0.7390.65141.0.7390.65
NVDgoogle/chrome< 141.0.7390.65
debiandebian/chromium< chromium 141.0.7390.65-1~deb12u1 (bookworm)
Debianchromium/chromium< 141.0.7390.65-1~deb12u1+2

🔴Vulnerability Details

2
GHSA
GHSA-fxpm-h77m-v8vc: Heap buffer overflow in Sync in Google Chrome prior to 1412025-11-07
OSV
CVE-2025-11458: Heap buffer overflow in Sync in Google Chrome prior to 1412025-11-06

📋Vendor Advisories

4
Red Hat
chromium-browser: Heap buffer overflow in Sync2025-11-06
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2025-114582025-10-15
Microsoft
Chromium: CVE-2025-11458 Heap buffer overflow in Sync2025-10-14
Debian
CVE-2025-11458: chromium - Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a r...2025

🕵️Threat Intelligence

3
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review | Qualys2025-10-14
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review2025-10-14
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14