CVE-2025-11211: Out of bounds read in WebCodecs
Chromium: CVE-2025-11211 Out of bounds read in Media
Other sources
Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141.0.7390.65 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 141.0.7390.54
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11211?
CVE-2025-11211 is classified as a high severity vulnerability due to the potential impact of an out of bounds read in Chromium-based browsers.
How do I fix CVE-2025-11211?
To fix CVE-2025-11211, update to the latest version of Microsoft Edge that includes the security patch for this vulnerability.
Which versions of Microsoft Edge are affected by CVE-2025-11211?
CVE-2025-11211 affects Microsoft Edge versions prior to 141.0.3537.57.
Is CVE-2025-11211 specific to any browser?
CVE-2025-11211 specifically affects Chromium-based browsers, including Microsoft Edge.
Where can I find more information about CVE-2025-11211?
More information about CVE-2025-11211 can be found in the release notes for Google Chrome.