CVE-2025-11460 is a use-after-free vulnerability in the Storage component of Google Chrome affecting versions prior to 141.0.7390.65. The flaw can be triggered by a remote attacker through delivery of a crafted video file, leading to memory corruption in the browser process. Due to the nature of use-after-free conditions, stale object references may be dereferenced after the underlying memory has been released, creating a path to controlled memory reuse and arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept exploit support repo for CVE-2025-11460, a Chromium IndexedDB use-after-free that can be triggered from a malicious webpage and reaches the unsandboxed browser process via Mojo IPC. The repo does not contain a complete standalone exploit webpage in the provided snapshot; instead, it contains supporting scripts and source patches used to prepare a vulnerable/instrumented Chromium build for exploitation and demonstration. Repository structure: README.md explains the vulnerability, exploitation concept, and reproduction workflow. disable_aslr.py is a Python utility that modifies a Windows PE executable to clear the ASLR bit and writes a new .noaslr executable, improving exploit reliability. copy_mojo_js_bindings.py recursively copies mojo_bindings.js and generated .mojom.js files from a Chromium build tree into a PoC web directory so the browser-side exploit page can use Mojo JS interfaces. renderer.patch changes Blink's IndexedDB deleteDatabase() path to force force_close=true, likely making the vulnerable race easier to trigger deterministically. v8.patch is the most security-relevant code artifact: it adds a global JavaScript object named POCHelper to V8 with helper methods getBaseOf, readBits, and writeBits, enabling direct module base discovery and arbitrary memory read/write from JavaScript in a custom build. Main exploit capability: the intended chain is browser/web-based exploitation of an IndexedDB UAF to gain code execution in the browser process. The included V8 patch effectively supplies post-corruption primitives for memory access, making the PoC operational rather than a pure crash reproducer. The README states the demonstrated result is spawning cmd and calc on Windows. Because the actual HTML/JS trigger is not present here, this repo is best understood as exploit-enablement infrastructure and patch set for a custom Chromium build rather than a turnkey public exploit. Notable observables and targets: the only explicit network endpoint is a locally hosted PoC at http://localhost:1337 served with python -m http.server 1337. The exploit targets Chromium/Chrome on Windows, requires MojoJS to be enabled, and depends on local files such as chrome.exe/chrome.noaslr.exe and copied Mojo JS bindings. No external C2, hardcoded remote IPs, or exfiltration endpoints are present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.