CVE-2025-11460

Description

Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code via a crafted video file. (Chromium security severity: High)

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.12

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-11458,CVE-2025-11460,CVE-2025-11211 are fixed in Google Chrome (141.0.7390.65,141.0.7390.66)Windows
Vulnerabilities CVE-2025-11458,CVE-2025-11460,CVE-2025-11211 are fixed in Google Chrome (x64) (141.0.7390.65,141.0.7390.66)Windows
Vulnerabilities CVE-2025-11458,CVE-2025-11460 are fixed in Microsoft Edge for chromium business (141.0.3537.71) (x86)Windows
Vulnerabilities CVE-2025-11458,CVE-2025-11460 are fixed in Microsoft Edge for chromium business (141.0.3537.71) (x64)Windows
Vulnerabilities CVE-2025-11458,CVE-2025-11460,CVE-2025-11211 are fixed in Google Chrome for Mac (141.0.7390.65, 141.0.7390.66)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-352193Google Chrome (141.0.7390.65,141.0.7390.66)
PATCH-352194Google Chrome (x64) (141.0.7390.65,141.0.7390.66)
PATCH-42592Microsoft Edge for chromium business (141.0.3537.71) (x86)
PATCH-42593Microsoft Edge for chromium business (141.0.3537.71) (x64)
PATCH-613261Google Chrome for Mac (144.0.7559.59,144.0.7559.60)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234