CVE-2025-11206: High Heap buffer overflow in Video.
Chromium: CVE-2025-11206 Heap buffer overflow in Video
Other sources
Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11206?
CVE-2025-11206 is classified as a high-severity vulnerability due to potential exploitation through a heap buffer overflow in Video processing.
How do I fix CVE-2025-11206?
To fix CVE-2025-11206, update your Microsoft Edge (Chromium-based) to the latest version available.
Which products are affected by CVE-2025-11206?
CVE-2025-11206 affects Microsoft Edge versions up to 141.0.3537.57 and all Chromium-based versions of Edge.
What type of vulnerability is CVE-2025-11206?
CVE-2025-11206 is categorized as a heap buffer overflow vulnerability.
Who has mitigated CVE-2025-11206?
Google Chrome and Microsoft Edge (Chromium-based) have addressed and mitigated CVE-2025-11206 in their updates.