CVE-2025-11460Use After Free in Google Chrome

Severity
8.8HIGHNVD
EPSS
0.1%
top 73.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 6
Latest updateNov 7

Description

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome141.0.7390.65141.0.7390.65
NVDgoogle/chrome< 141.0.7390.65
Debianchromium/chromium< 141.0.7390.65-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-xr3x-3m9h-jg3r: Use after free in Storage in Google Chrome prior to 1412025-11-07
OSV
CVE-2025-11460: Use after free in Storage in Google Chrome prior to 1412025-11-06
CVEList
CVE-2025-11460: Use after free in Storage in Google Chrome prior to 1412025-11-06

📋Vendor Advisories

4
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-114602025-11-07
Red Hat
chromium-browser: Use after free in Storage2025-11-06
Microsoft
Chromium: CVE-2025-11460 Use after free in Storage2025-10-14
Debian
CVE-2025-11460: chromium - Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remo...2025

🕵️Threat Intelligence

3
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review | Qualys2025-10-14
Qualys
Microsoft and Adobe Patch Tuesday, October 2025 Security Update Review2025-10-14
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14
CVE-2025-11460 — Use After Free in Google Chrome | cvebase