Google released an urgent security update for its Chrome browser to address a critical vulnerability identified as CVE-2025-11756. This flaw was discovered in Chrome’s Safe Browsing component, a feature responsible for protecting users from malicious websites and harmful downloads. The vulnerability is classified as a use-after-free issue, which occurs when memory is accessed after it has been freed, potentially allowing attackers to execute arbitrary code on affected systems. If exploited, this vulnerability could enable cybercriminals to gain unauthorized access to a user’s device, install malware, exfiltrate sensitive data, or compromise user accounts. Google rated the severity of this vulnerability as High, underscoring the significant risk it poses to user privacy and system integrity. The issue was responsibly disclosed by a security researcher known as “asnine” on September 25, 2025, who was awarded $7,000 through Google’s bug bounty program for their contribution. Google publicly acknowledged the researcher’s efforts and emphasized the importance of collaboration with the security community in preventing such flaws from reaching end users. To mitigate the risk, Google released a security patch in Chrome version 141.0.7390.107/.108 for Windows and Mac, and version 141.0.7390.107 for Linux. Users were urged to update their browsers immediately to ensure protection against potential exploitation. The vulnerability’s presence in the Safe Browsing component is particularly concerning due to the elevated privileges with which this feature operates. Attackers leveraging this flaw could bypass key security controls, making prompt patching essential. The update was rolled out through Chrome’s standard update channels, and Google provided guidance for users to verify their browser version. No evidence of active exploitation in the wild was reported at the time of disclosure, but the public availability of the patch increased the urgency for users and organizations to apply the update. Security experts highlighted the ongoing risk posed by use-after-free vulnerabilities in modern browsers, noting that such flaws remain a common target for attackers. The incident reinforced the value of bug bounty programs in identifying and remediating critical security issues before they can be weaponized. Organizations were advised to ensure all endpoints running Chrome were updated promptly and to monitor for any signs of compromise. The swift response by Google demonstrated the company’s commitment to user security and the effectiveness of coordinated vulnerability disclosure.

See affected versions and whether adversaries are exploiting it.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.