Google Chrome Heap Buffer Overflow Vulnerability in Sync Component Allowing Out-of-Bounds Memory Read

Vulnerability

A heap buffer overflow vulnerability has been identified in the Sync component of Google Chrome. This issue affects versions prior to 141.0.7390.65. The vulnerability allows remote attackers to perform out-of-bounds memory reads by exploiting a crafted HTML page.

Impact

Exploitation of this vulnerability leads to a heap buffer overflow, allowing for out-of-bounds memory reads, which can potentially be exploited to execute arbitrary code or cause a denial-of-service condition.

Remediation

Users can update to Google Chrome version 141.0.7390.65 or later to address this vulnerability.

Added: Nov 6, 2025, 11:22 PM
Updated: Nov 6, 2025, 11:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.