Google 141 update available

The update fixes serious security vulnerabilities. The vulnerabilities potentially allow remote code execution within Chrome's sandbox.

Google has updated its Chrome browser to version 141. According to the release notes, the update includes patches for 21 security vulnerabilities. At least two vulnerabilities pose a high risk. They could potentially allow the remote injection and execution of malicious code within the browser's sandbox.

Google assigns a high rating to the vulnerabilities with the identifiers CVE-2025-11205 and CVE-2025-11206. Both are described as heap buffer overflows in the WebGPU and Video components, respectively.

Such vulnerabilities can typically be exploited via specially crafted HTML pages. An attacker simply needs to entice a victim to visit a website they control, for example, via a link in an email or text message.

Google provides details on a total of twelve vulnerabilities. They are found in components such as Storage, Media, Omnibox, and the JavaScript engine V8. This makes Chrome vulnerable to, among other things, remote code execution and the disclosure of confidential information.

Patches available for Chrome for Windows, macOS, and Linux

Google is paying $50,000 from its bounty program to the discoverers of the vulnerabilities. $25,000 of this will go to Finnish security researcher Atte Kettunen from the University of Oulu. The size of the reward is usually also an indication of the severity of a security vulnerability. Security provider Tenable, for example, classifies the bug reported by Kettunen as critical according to the Common Vulnerability Scoring System (CVSS) (opens in a new window).

Google is now automatically distributing the patches with the update to Chrome 141. Version 141.0.7390.54/.55 is available for download on Windows and macOS. Linux users should upgrade to version 141.0.7390.54 as soon as possible.

about author